Unauthorized Access to Arbitrary Files in Ivanti SmartDeviceServer 6.3.1
CVE-2024-38653
7.5HIGH
Summary
An XXE (XML External Entity) vulnerability exists in the SmartDeviceServer component of Ivanti Avalanche 6.3.1. This allows a remote unauthenticated attacker to exploit the issue and gain unauthorized access to read arbitrary files stored on the server. This vulnerability poses a risk to the security of sensitive data managed within the Ivanti Avalanche environment, highlighting the importance of immediate patching and risk mitigation strategies.
Affected Version(s)
Avalanche 6.4.4
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved