CVE-2024-47010
moderateUnauthenticated Path Traversal Authentication Bypass in Ivanti Avalanche
Ivanti Avalanche versions before 6.4.5 contain a path traversal flaw (CWE-22) in an accessible network-facing component that allows a remote, unauthenticated attacker to bypass authentication (CWE-288). An attacker triggers it by sending crafted requests containing directory traversal sequences to the affected service without any valid credentials. Successful exploitation defeats the authentication control on the console interface, giving the attacker access to protected functionality, with the CVSS 9.8 score indicating high impact on confidentiality, integrity, and availability. Any organization running an affected release of Ivanti Avalanche, an on-premises mobile device management platform, is exposed, particularly where the console is reachable from untrusted networks. As of now there is no known public proof-of-concept or confirmed in-the-wild exploitation, but the high EPSS score (37.8%, 98th percentile) indicates an elevated probability of exploitation activity within the next 30 days.
What to do: Upgrade Ivanti Avalanche to version 6.4.5 or later as the primary fix. Until patched, restrict network access to the Avalanche console so unauthenticated endpoints are reachable only from trusted management networks, and check for any internet-facing Avalanche instances in your exposure scans. Monitor Ivanti advisories for follow-up guidance given the elevated EPSS score.
| Ivanti Avalanche | All versions prior to 6.4.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
- Vendors
- ivanti
- Products
- avalanche
- Weakness
- CWE-22, CWE-288
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.