CVE-2024-50320
nicheInfinite Loop DoS in Ivanti Avalanche before 6.4.6
CVE-2024-50320 is an infinite loop (CWE-835) in Ivanti Avalanche, the vendor's enterprise mobile device management platform, affecting all versions before 6.4.6. A remote, unauthenticated attacker can trigger the loop by sending network requests to the Avalanche service, causing it to hang. The result is a denial of service: the affected service stops responding until it is restarted, with no confidentiality or integrity impact per the CVSS scoring (C:N/I:N/A:H). Any organization running an unpatched Ivanti Avalanche deployment is exposed, though deployments of this on-premises enterprise MDM are typically internal-facing. As of now there is no known public proof-of-concept, the flaw is not in CISA's KEV, and no confirmed in-the-wild exploitation has been reported, but EPSS puts its probability of exploitation within 30 days at about 40% (99th percentile).
What to do: Upgrade Ivanti Avalanche to version 6.4.6 or later. Where patching is not immediately possible, restrict network access to the Avalanche server so untrusted clients cannot reach it, and monitor Ivanti's advisory for updates. Given the elevated EPSS score, prioritize this fix even though no active exploitation has been confirmed.
| Ivanti Avalanche | all versions before 6.4.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
- Vendors
- ivanti
- Products
- avalanche
- Weakness
- CWE-835
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.