ZeroHour

CVE-2024-47011

moderate

Unauthenticated Path Traversal in Ivanti Avalanche before 6.4.5

CVSS 3.1
7.5 high
EPSS
56%p99
Published
()
Modified
AI analysis

Ivanti Avalanche, an on-premises mobile device management platform used to administer fleets of mobile and ruggedized devices, is vulnerable to a path traversal flaw (CWE-22) in versions prior to 6.4.5. A remote, unauthenticated attacker can send crafted requests containing directory-traversal sequences to move outside the intended directory and read files on the server. Successful exploitation results in disclosure of sensitive information, such as configuration data, without affecting integrity or availability (CVSS 7.5: network vector, no privileges or user interaction required). All organizations running Ivanti Avalanche before version 6.4.5 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS places it at the 99th percentile with a 56.3% probability of exploitation within 30 days, so attackers are likely to target it soon.

What to do: Upgrade Ivanti Avalanche to version 6.4.5 or later. Until patched, ensure the Avalanche management interfaces are not exposed to the internet and restrict access to trusted internal networks or VPN clients. Given Ivanti products are a frequent exploitation target and the elevated EPSS score, prioritize this patch and review the server's logs for signs of directory-traversal file-read activity.

Affected
Ivanti AvalancheAll versions before 6.4.5
Estimated exposure
moderatelikely low thousands of internet-exposed Avalanche consoles worldwide (on-prem enterprise MDM; public install-base figures not published) — Avalanche is an on-premises enterprise MDM typically deployed as a single management server per organization (commonly for warehouse, retail, and logistics mobile-device fleets), so the internet-exposed footprint is plausibly in the low…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information

Vendors
ivanti
Products
avalanche
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.