CVE-2024-47011
moderateUnauthenticated Path Traversal in Ivanti Avalanche before 6.4.5
Ivanti Avalanche, an on-premises mobile device management platform used to administer fleets of mobile and ruggedized devices, is vulnerable to a path traversal flaw (CWE-22) in versions prior to 6.4.5. A remote, unauthenticated attacker can send crafted requests containing directory-traversal sequences to move outside the intended directory and read files on the server. Successful exploitation results in disclosure of sensitive information, such as configuration data, without affecting integrity or availability (CVSS 7.5: network vector, no privileges or user interaction required). All organizations running Ivanti Avalanche before version 6.4.5 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS places it at the 99th percentile with a 56.3% probability of exploitation within 30 days, so attackers are likely to target it soon.
What to do: Upgrade Ivanti Avalanche to version 6.4.5 or later. Until patched, ensure the Avalanche management interfaces are not exposed to the internet and restrict access to trusted internal networks or VPN clients. Given Ivanti products are a frequent exploitation target and the elevated EPSS score, prioritize this patch and review the server's logs for signs of directory-traversal file-read activity.
| Ivanti Avalanche | All versions before 6.4.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
- Vendors
- ivanti
- Products
- avalanche
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.