ZeroHour

CVE-2024-13179

moderate

Authentication Bypass via Path Traversal in Ivanti Avalanche before 6.4.7

CVSS 3.1
9.8 critical
EPSS
63%p99
Published
()
Modified
AI analysis

CVE-2024-13179 is a path traversal flaw (CWE-22) in Ivanti Avalanche, Ivanti's on-premises mobile device management (MDM) platform, that a remote unauthenticated attacker can abuse to bypass authentication (CWE-288). It is triggered over the network with no privileges or user interaction by sending a crafted request containing path traversal sequences to the vulnerable Avalanche service. Successful exploitation lets the attacker reach the application without valid credentials; the critical 9.8 CVSS score reflects high impact to confidentiality, integrity, and availability once the bypass is achieved. Any organization running an Ivanti Avalanche server in a version before 6.4.7 is affected, including deployments exposed directly to the internet or reachable from less-trusted network zones. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 63% EPSS score (99th percentile) indicates a high probability of exploitation within the next 30 days.

What to do: Upgrade Ivanti Avalanche to version 6.4.7 or later as soon as possible. Until patched, restrict network access to the Avalanche web/admin service (commonly TCP 5991) to trusted management networks and review logs for anomalous requests containing path traversal patterns. Given the 63% EPSS probability, treat this patch as urgent.

Affected
Ivanti Avalancheall versions before 6.4.7
Estimated exposure
moderate≈ a low thousands of on-premises server deployments, with a subset directly internet-exposed (estimate) — Avalanche is a specialized enterprise MDM used to manage fleets of rugged/mobile devices in warehousing, retail, and logistics, so its installed base follows enterprise deployment patterns (low thousands of server installations) rather…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.

Vendors
ivanti
Products
avalanche
Weakness
CWE-22, CWE-288
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.