Ivanti Avalanche 6.1.106.496 Premise Edition

CPE Details

Ivanti Avalanche 6.1.106.496 Premise Edition
6.1.106.496
2023-05-16
12h53 +00:00
2023-06-20
14h57 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:ivanti:avalanche:6.1.106.496:*:*:*:premise:*:*:*

Informations

Vendor

ivanti

Product

avalanche

Version

6.1.106.496

Software Edition

premise

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-13181 2025-01-14 16h53 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.
9.8
Critique
CVE-2024-13180 2025-01-14 16h52 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.
7.5
Haute
CVE-2024-13179 2025-01-14 16h51 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.
9.8
Critique
CVE-2024-50331 2024-11-12 15h34 +00:00 An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.
7.5
Haute
CVE-2024-50321 2024-11-12 15h33 +00:00 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
Haute
CVE-2024-50320 2024-11-12 15h32 +00:00 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
Haute
CVE-2024-50319 2024-11-12 15h32 +00:00 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
Haute
CVE-2024-50318 2024-11-12 15h30 +00:00 A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
Haute
CVE-2024-50317 2024-11-12 15h29 +00:00 A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
Haute
CVE-2024-47011 2024-10-08 16h30 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
7.5
Haute
CVE-2024-47010 2024-10-08 16h29 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
9.8
Critique
CVE-2024-47009 2024-10-08 16h28 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
9.8
Critique
CVE-2024-47008 2024-10-08 16h28 +00:00 Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.
7.5
Haute
CVE-2024-47007 2024-10-08 16h27 +00:00 A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.
7.5
Haute
CVE-2023-46220 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46261 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46260 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46266 2023-12-19 15h43 +00:00 An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
9.1
Critique
CVE-2023-46258 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46803 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).
7.5
Haute
CVE-2023-46264 2023-12-19 15h43 +00:00 An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
9.8
Critique
CVE-2023-46224 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46262 2023-12-19 15h43 +00:00 An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server.
7.5
Haute
CVE-2023-46221 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46216 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46222 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-41727 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46217 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46265 2023-12-19 15h43 +00:00 An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).
9.8
Critique
CVE-2023-46257 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46804 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).
7.5
Haute
CVE-2023-46263 2023-12-19 15h43 +00:00 An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.
9.8
Critique
CVE-2023-46225 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46259 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46223 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2021-22962 2023-12-19 15h43 +00:00 An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
9.1
Critique
CVE-2023-41726 2023-11-03 18h13 +00:00 Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability
7.8
Haute
CVE-2023-41725 2023-11-03 18h13 +00:00 Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability
7.8
Haute
CVE-2022-43554 2023-11-03 18h13 +00:00 Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability
7.8
Haute
CVE-2022-43555 2023-11-03 18h13 +00:00 Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability
7.8
Haute
CVE-2023-32560 2023-08-10 19h07 +00:00 An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.
9.8
Critique
CVE-2023-32561 2023-08-10 19h07 +00:00 A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authentication bypass. Fixed in version 6.4.1.
7.5
Haute
CVE-2023-32562 2023-08-10 19h04 +00:00 An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.
9.8
Critique
CVE-2023-32563 2023-08-10 19h04 +00:00 An unauthenticated attacker could achieve the code execution through a RemoteControl server.
9.8
Critique
CVE-2023-32564 2023-08-10 19h04 +00:00 An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
9.8
Critique
CVE-2023-32565 2023-08-10 19h03 +00:00 An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.
9.1
Critique
CVE-2023-32566 2023-08-10 18h58 +00:00 An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.
9.1
Critique
CVE-2023-32567 2023-08-10 18h58 +00:00 Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236
9.8
Critique
CVE-2023-28125 2023-05-09 00h00 +00:00 An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.
5.9
Moyen
CVE-2023-28126 2023-05-09 00h00 +00:00 An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.
5.9
Moyen
CVE-2023-28127 2023-05-09 00h00 +00:00 A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure.
7.5
Haute
CVE-2023-28128 2023-05-09 00h00 +00:00 An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.
7.2
Haute
CVE-2022-44574 2023-03-10 00h00 +00:00 An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port.
7.5
Haute
CVE-2021-42133 2021-12-07 12h13 +00:00 An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform an arbitrary file write.
8.1
Haute
CVE-2021-42132 2021-12-07 12h13 +00:00 A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
8.8
Haute
CVE-2021-42131 2021-12-07 12h13 +00:00 A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
8.8
Haute
CVE-2021-42130 2021-12-07 12h13 +00:00 A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.
8.8
Haute
CVE-2021-42129 2021-12-07 12h13 +00:00 A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
8.8
Haute
CVE-2021-42128 2021-12-07 12h13 +00:00 An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.
9.8
Critique
CVE-2021-42127 2021-12-07 12h13 +00:00 A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
9.8
Critique
CVE-2021-42126 2021-12-07 12h12 +00:00 An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
8.8
Haute
CVE-2021-42125 2021-12-07 12h12 +00:00 An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.
8.8
Haute
CVE-2021-42124 2021-12-07 12h12 +00:00 An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.
8.8
Haute
CVE-2018-8901 2018-06-29 13h00 +00:00 An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. These passwords are stored in the Avalanche databases. This issue only affects customers who have enabled LDAP authentication in their configuration.
7.8
Haute
CVE-2018-8902 2018-06-29 13h00 +00:00 An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to encrypt data. A user with access to system databases can use the discovered key to access potentially confidential stored data, which may include Wi-Fi passwords. This discovered key can be used for all instances of the product.
6.5
Moyen