PT-2024-4020 · Ivanti · Ivanti Avalanche

Published

2024-04-24

·

Updated

2025-05-06

·

CVE-2024-29848

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Ivanti Avalanche versions prior to 6.4.x
Description: The issue is related to an unrestricted file upload vulnerability in the web component of Ivanti Avalanche. This vulnerability allows an authenticated, privileged user to execute arbitrary commands as SYSTEM. It can be exploited by a remote attacker to execute arbitrary code by uploading a specially crafted file.
Recommendations: For versions prior to 6.4.x, update to version 6.4.x or later to resolve the issue. As a temporary workaround, consider restricting file uploads to only necessary and validated files to minimize the risk of exploitation. Restrict access to the FileStoreConfig component to minimize the risk of exploitation. Avoid using the FileStoreConfig component until the issue is resolved.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2024-04453
CVE-2024-29848
ZDI-24-504

Affected Products

Ivanti Avalanche