ZeroHour

CVE-2024-13181

niche

Unauthenticated Path Traversal Authentication Bypass in Ivanti Avalanche

CVSS 3.1
9.8 critical
EPSS
32%p98
Published
()
Modified
AI analysis

Ivanti Avalanche, an enterprise warehouse-management and mobile device platform, contains a path traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to bypass authentication (CWE-288). The flaw is reachable over the network with no privileges or user interaction required, earning a critical 9.8 CVSS score. All Avalanche versions prior to 6.4.7 are affected, and this advisory specifically resolves an incomplete fix for CVE-2024-47010, meaning sites that already patched that earlier flaw may still be vulnerable. A successful attacker can gain authenticated access without valid credentials, with the CVSS vector indicating high potential impact to confidentiality, integrity, and availability. No public proof-of-concept or confirmed in-the-wild exploitation is known, though the elevated EPSS score of 32.4% (98th percentile) indicates a high likelihood of exploitation within the next 30 days.

What to do: Upgrade Ivanti Avalanche to version 6.4.7 or later; sites that already applied the CVE-2024-47010 fix should still upgrade because that fix was incomplete. Until patched, restrict access to Avalanche's network services to trusted management networks and watch for unexplained authenticated activity. Given the elevated EPSS probability, prioritize this update promptly even though no public exploit is known.

Affected
Ivanti AvalancheAll versions before 6.4.7 (including systems whose earlier CVE-2024-47010 fix was incomplete)
Estimated exposure
nicheLow thousands of enterprise deployments (order-of-magnitude estimate) — Ivanti Avalanche is a niche, enterprise warehouse-management product typically deployed on-premises at enterprise sites rather than at consumer scale, so the installed base is plausibly in the low thousands of deployments with only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.

Vendors
ivanti
Products
avalanche
Weakness
CWE-22, CWE-288
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.