ZeroHour

CVE-2024-50320

niche

Infinite Loop DoS in Ivanti Avalanche before 6.4.6

CVSS 3.1
7.5 high
EPSS
40%p99
Published
()
Modified
AI analysis

CVE-2024-50320 is an infinite loop (CWE-835) in Ivanti Avalanche, the vendor's enterprise mobile device management platform, affecting all versions before 6.4.6. A remote, unauthenticated attacker can trigger the loop by sending network requests to the Avalanche service, causing it to hang. The result is a denial of service: the affected service stops responding until it is restarted, with no confidentiality or integrity impact per the CVSS scoring (C:N/I:N/A:H). Any organization running an unpatched Ivanti Avalanche deployment is exposed, though deployments of this on-premises enterprise MDM are typically internal-facing. As of now there is no known public proof-of-concept, the flaw is not in CISA's KEV, and no confirmed in-the-wild exploitation has been reported, but EPSS puts its probability of exploitation within 30 days at about 40% (99th percentile).

What to do: Upgrade Ivanti Avalanche to version 6.4.6 or later. Where patching is not immediately possible, restrict network access to the Avalanche server so untrusted clients cannot reach it, and monitor Ivanti's advisory for updates. Given the elevated EPSS score, prioritize this fix even though no active exploitation has been confirmed.

Affected
Ivanti Avalancheall versions before 6.4.6
Estimated exposure
nichelikely on the order of thousands of enterprise deployments (no public install counts available) — Ivanti Avalanche is an on-premises enterprise MDM used to manage fleets of rugged and mobile devices, so exposure is limited to enterprise server deployments rather than mass-market installs, and its typically internal placement keeps the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

Vendors
ivanti
Products
avalanche
Weakness
CWE-835
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.