Ivanti Avalanche 6.4.2 Premise Edition

CPE Details

Ivanti Avalanche 6.4.2 Premise Edition
6.4.2
2023-12-29
09h15 +00:00
2023-12-29
09h15 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ivanti:avalanche:6.4.2:*:*:*:premise:*:*:*

Informations

Vendor

ivanti

Product

avalanche

Version

6.4.2

Software Edition

premise

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-13181 2025-01-14 16h53 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.
9.8
Critical
CVE-2024-13180 2025-01-14 16h52 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.
7.5
High
CVE-2024-13179 2025-01-14 16h51 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.
9.8
Critical
CVE-2024-50331 2024-11-12 15h34 +00:00 An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.
7.5
High
CVE-2024-50321 2024-11-12 15h33 +00:00 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
High
CVE-2024-50320 2024-11-12 15h32 +00:00 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
High
CVE-2024-50319 2024-11-12 15h32 +00:00 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
High
CVE-2024-50318 2024-11-12 15h30 +00:00 A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
High
CVE-2024-50317 2024-11-12 15h29 +00:00 A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
High
CVE-2024-47011 2024-10-08 16h30 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
7.5
High
CVE-2024-47010 2024-10-08 16h29 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
9.8
Critical
CVE-2024-47009 2024-10-08 16h28 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
9.8
Critical
CVE-2024-47008 2024-10-08 16h28 +00:00 Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.
7.5
High
CVE-2024-47007 2024-10-08 16h27 +00:00 A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.
7.5
High
CVE-2024-38652 2024-08-14 02h38 +00:00 Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.
9.1
Critical
CVE-2024-37373 2024-08-14 02h38 +00:00 Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
7.2
High
CVE-2024-37399 2024-08-14 02h38 +00:00 A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
7.5
High
CVE-2024-38653 2024-08-14 02h38 +00:00 XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
7.5
High
CVE-2024-36136 2024-08-14 02h38 +00:00 An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
7.5
High