PT-2024-2917 · Ivanti · Ivanti Avalanche

Published

2024-03-18

·

Updated

2024-07-03

·

CVE-2024-23528

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ivanti Avalanche versions prior to 6.4.3
Description An out-of-bounds read issue in the WLAvalancheService component can allow an unauthenticated remote attacker to read sensitive information in memory under certain conditions.
Recommendations For versions prior to 6.4.3, update to version 6.4.3 or later to resolve the issue.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2024-03082
CVE-2024-23528
ZDI-24-373

Affected Products

Ivanti Avalanche