ZeroHour

CVE-2024-47008

large

Unauthenticated SSRF in Ivanti Avalanche

CVSS 3.1
7.5 high
EPSS
47%p99
Published
()
Modified
AI analysis

CVE-2024-47008 is a server-side request forgery (SSRF, CWE-918) flaw in Ivanti Avalanche, an enterprise mobile device management platform for ruggedized and mobile devices, affecting versions before 6.4.5. A remote, unauthenticated attacker can trigger the flaw over the network by sending a crafted request that causes the Avalanche server to issue requests to attacker-controlled or internal resources. Successful exploitation allows the attacker to leak sensitive information from the server or the internal network, with high confidentiality impact but no integrity or availability impact per the CVSS vector. Organizations running any Ivanti Avalanche release prior to 6.4.5 are affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, but the high EPSS score (47.1% within 30 days, 99th percentile) indicates an elevated likelihood of exploitation in the near term.

What to do: Upgrade Ivanti Avalanche to version 6.4.5 or later. Until patched, restrict access to the Avalanche console to trusted networks or VPN access, apply egress filtering from the server to limit SSRF reach, and review outbound request logs for signs of SSRF probing. Verify whether any Avalanche instances are exposed to the internet and remediate that exposure first.

Affected
Ivanti Avalanchebefore 6.4.5
Estimated exposure
largetens of thousands of on-prem deployments, with only a subset likely internet-exposed — Ivanti Avalanche is an on-premises enterprise MDM typically deployed inside corporate networks managing fleets of ruggedized devices; no public install counts exist, so the estimate reflects its established enterprise footprint and the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

Vendors
ivanti
Products
avalanche
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.