Remote Denial of Service Vulnerability in Ivanti Avalanche Before 6.4.5
CVE-2024-47007
7.5HIGH
What is CVE-2024-47007?
A vulnerability exists in Ivanti Avalanche before version 6.4.5, specifically in the WLAvalancheService.exe component, where a NULL pointer dereference can occur. This security flaw allows remote, unauthenticated attackers to potentially trigger a denial of service, disrupting the availability of the service. Organizations utilizing this software should assess their current version and consider upgrading to mitigate associated risks.
Affected Version(s)
Avalanche 6.4.5