PT-2024-2918 · Ivanti · Ivanti Avalanche

Published

2024-03-18

·

Updated

2025-05-06

·

CVE-2024-27984

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions Ivanti Avalanche versions prior to 6.4.3
Description The issue is related to a Path Traversal vulnerability in the web component of Ivanti Avalanche. This vulnerability allows a remote authenticated attacker to delete specific types of files and/or cause denial of service. The vulnerability is associated with incorrect restriction of the path name to a directory with limited access. Exploitation of the vulnerability can allow a remote attacker to cause a denial of service.
Recommendations For versions prior to 6.4.3, update to version 6.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the WLInfoRailService to minimize the risk of exploitation. Avoid using the DELKEY function in the affected service until the issue is resolved.

Fix

DoS

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-03083
CVE-2024-27984
ZDI-24-395

Affected Products

Ivanti Avalanche