CVE-2024-47008
largeUnauthenticated SSRF in Ivanti Avalanche
CVE-2024-47008 is a server-side request forgery (SSRF, CWE-918) flaw in Ivanti Avalanche, an enterprise mobile device management platform for ruggedized and mobile devices, affecting versions before 6.4.5. A remote, unauthenticated attacker can trigger the flaw over the network by sending a crafted request that causes the Avalanche server to issue requests to attacker-controlled or internal resources. Successful exploitation allows the attacker to leak sensitive information from the server or the internal network, with high confidentiality impact but no integrity or availability impact per the CVSS vector. Organizations running any Ivanti Avalanche release prior to 6.4.5 are affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, but the high EPSS score (47.1% within 30 days, 99th percentile) indicates an elevated likelihood of exploitation in the near term.
What to do: Upgrade Ivanti Avalanche to version 6.4.5 or later. Until patched, restrict access to the Avalanche console to trusted networks or VPN access, apply egress filtering from the server to limit SSRF reach, and review outbound request logs for signs of SSRF probing. Verify whether any Avalanche instances are exposed to the internet and remediate that exposure first.
| Ivanti Avalanche | before 6.4.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.
- Vendors
- ivanti
- Products
- avalanche
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.