ZeroHour

CVE-2024-47010

moderate

Unauthenticated Path Traversal Authentication Bypass in Ivanti Avalanche

CVSS 3.1
9.8 critical
EPSS
38%p98
Published
()
Modified
AI analysis

Ivanti Avalanche versions before 6.4.5 contain a path traversal flaw (CWE-22) in an accessible network-facing component that allows a remote, unauthenticated attacker to bypass authentication (CWE-288). An attacker triggers it by sending crafted requests containing directory traversal sequences to the affected service without any valid credentials. Successful exploitation defeats the authentication control on the console interface, giving the attacker access to protected functionality, with the CVSS 9.8 score indicating high impact on confidentiality, integrity, and availability. Any organization running an affected release of Ivanti Avalanche, an on-premises mobile device management platform, is exposed, particularly where the console is reachable from untrusted networks. As of now there is no known public proof-of-concept or confirmed in-the-wild exploitation, but the high EPSS score (37.8%, 98th percentile) indicates an elevated probability of exploitation activity within the next 30 days.

What to do: Upgrade Ivanti Avalanche to version 6.4.5 or later as the primary fix. Until patched, restrict network access to the Avalanche console so unauthenticated endpoints are reachable only from trusted management networks, and check for any internet-facing Avalanche instances in your exposure scans. Monitor Ivanti advisories for follow-up guidance given the elevated EPSS score.

Affected
Ivanti AvalancheAll versions prior to 6.4.5
Estimated exposure
moderate≈1,000–10,000 deployments (enterprise on-prem MDM installs; only a subset of consoles internet-exposed) — Avalanche is a specialized enterprise MDM used to manage ruggedized/mobile device fleets, typically deployed on-premises, so the installed base is in the low tens of thousands with public internet exposure limited to a smaller fraction of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

Vendors
ivanti
Products
avalanche
Weakness
CWE-22, CWE-288
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.