PT-2024-2923 · Ivanti · Ivanti Avalanche

Published

2024-03-18

·

Updated

2024-07-03

·

CVE-2024-23533

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ivanti Avalanche versions prior to 6.4.3
Description The issue is related to an out-of-bounds read in the WLAvalancheService component. This can allow an authenticated remote attacker to read sensitive information in memory under certain conditions.
Recommendations For versions prior to 6.4.3, update to version 6.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the WLAvalancheService component until a patch is applied.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2024-03088
CVE-2024-23533
ZDI-24-377

Affected Products

Ivanti Avalanche