CVE-2024-13181
nicheUnauthenticated Path Traversal Authentication Bypass in Ivanti Avalanche
Ivanti Avalanche, an enterprise warehouse-management and mobile device platform, contains a path traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to bypass authentication (CWE-288). The flaw is reachable over the network with no privileges or user interaction required, earning a critical 9.8 CVSS score. All Avalanche versions prior to 6.4.7 are affected, and this advisory specifically resolves an incomplete fix for CVE-2024-47010, meaning sites that already patched that earlier flaw may still be vulnerable. A successful attacker can gain authenticated access without valid credentials, with the CVSS vector indicating high potential impact to confidentiality, integrity, and availability. No public proof-of-concept or confirmed in-the-wild exploitation is known, though the elevated EPSS score of 32.4% (98th percentile) indicates a high likelihood of exploitation within the next 30 days.
What to do: Upgrade Ivanti Avalanche to version 6.4.7 or later; sites that already applied the CVE-2024-47010 fix should still upgrade because that fix was incomplete. Until patched, restrict access to Avalanche's network services to trusted management networks and watch for unexplained authenticated activity. Given the elevated EPSS probability, prioritize this update promptly even though no public exploit is known.
| Ivanti Avalanche | All versions before 6.4.7 (including systems whose earlier CVE-2024-47010 fix was incomplete) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.
- Vendors
- ivanti
- Products
- avalanche
- Weakness
- CWE-22, CWE-288
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.