CVE-2024-13179
moderateAuthentication Bypass via Path Traversal in Ivanti Avalanche before 6.4.7
CVE-2024-13179 is a path traversal flaw (CWE-22) in Ivanti Avalanche, Ivanti's on-premises mobile device management (MDM) platform, that a remote unauthenticated attacker can abuse to bypass authentication (CWE-288). It is triggered over the network with no privileges or user interaction by sending a crafted request containing path traversal sequences to the vulnerable Avalanche service. Successful exploitation lets the attacker reach the application without valid credentials; the critical 9.8 CVSS score reflects high impact to confidentiality, integrity, and availability once the bypass is achieved. Any organization running an Ivanti Avalanche server in a version before 6.4.7 is affected, including deployments exposed directly to the internet or reachable from less-trusted network zones. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 63% EPSS score (99th percentile) indicates a high probability of exploitation within the next 30 days.
What to do: Upgrade Ivanti Avalanche to version 6.4.7 or later as soon as possible. Until patched, restrict network access to the Avalanche web/admin service (commonly TCP 5991) to trusted management networks and review logs for anomalous requests containing path traversal patterns. Given the 63% EPSS probability, treat this patch as urgent.
| Ivanti Avalanche | all versions before 6.4.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.
- Vendors
- ivanti
- Products
- avalanche
- Weakness
- CWE-22, CWE-288
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.