Ivanti Avalanche 6.4.1 Premise Edition

CPE Details

Ivanti Avalanche 6.4.1 Premise Edition
6.4.1
2024-01-13
04h00 +00:00
2024-01-13
04h00 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:ivanti:avalanche:6.4.1:*:*:*:premise:*:*:*

Informations

Vendor

ivanti

Product

avalanche

Version

6.4.1

Software Edition

premise

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-13181 2025-01-14 16h53 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.
9.8
Critique
CVE-2024-13180 2025-01-14 16h52 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.
7.5
Haute
CVE-2024-13179 2025-01-14 16h51 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.
9.8
Critique
CVE-2024-50331 2024-11-12 15h34 +00:00 An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.
7.5
Haute
CVE-2024-50321 2024-11-12 15h33 +00:00 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
Haute
CVE-2024-50320 2024-11-12 15h32 +00:00 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
Haute
CVE-2024-50319 2024-11-12 15h32 +00:00 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
Haute
CVE-2024-50318 2024-11-12 15h30 +00:00 A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
Haute
CVE-2024-50317 2024-11-12 15h29 +00:00 A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
Haute
CVE-2024-47011 2024-10-08 16h30 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
7.5
Haute
CVE-2024-47010 2024-10-08 16h29 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
9.8
Critique
CVE-2024-47009 2024-10-08 16h28 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
9.8
Critique
CVE-2024-47008 2024-10-08 16h28 +00:00 Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.
7.5
Haute
CVE-2024-47007 2024-10-08 16h27 +00:00 A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.
7.5
Haute
CVE-2024-38652 2024-08-14 02h38 +00:00 Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.
9.1
Critique
CVE-2024-37373 2024-08-14 02h38 +00:00 Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
7.2
Haute
CVE-2024-37399 2024-08-14 02h38 +00:00 A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
7.5
Haute
CVE-2024-38653 2024-08-14 02h38 +00:00 XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
7.5
Haute
CVE-2024-36136 2024-08-14 02h38 +00:00 An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
7.5
Haute
CVE-2023-46220 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46261 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46260 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46266 2023-12-19 15h43 +00:00 An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
9.1
Critique
CVE-2023-46258 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46803 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).
7.5
Haute
CVE-2023-46264 2023-12-19 15h43 +00:00 An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
9.8
Critique
CVE-2023-46224 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46262 2023-12-19 15h43 +00:00 An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server.
7.5
Haute
CVE-2023-46221 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46216 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46222 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-41727 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46217 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46265 2023-12-19 15h43 +00:00 An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).
9.8
Critique
CVE-2023-46257 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46804 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).
7.5
Haute
CVE-2023-46263 2023-12-19 15h43 +00:00 An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.
9.8
Critique
CVE-2023-46225 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46259 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2023-46223 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critique
CVE-2021-22962 2023-12-19 15h43 +00:00 An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
9.1
Critique
CVE-2023-41726 2023-11-03 18h13 +00:00 Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability
7.8
Haute
CVE-2023-41725 2023-11-03 18h13 +00:00 Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability
7.8
Haute
CVE-2022-43554 2023-11-03 18h13 +00:00 Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability
7.8
Haute
CVE-2022-43555 2023-11-03 18h13 +00:00 Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability
7.8
Haute