ZeroHour

CVE-2024-29848

CVSS 3.1
7.2 high
EPSS
64%p99
Published
()
Modified
Description

An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.

Vendors
ivanti
Products
avalanche
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news