PT-2024-6877 · Ivanti · Ivanti Avalanche

Published

2024-04-17

·

Updated

2025-11-17

·

CVE-2024-47008

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ivanti Avalanche versions prior to 6.4.5
Description A server-side request forgery issue exists in the validateAMCWSConnection function of Ivanti Avalanche. This flaw allows a remote, unauthenticated attacker to disclose sensitive information by exploiting insufficient validation of incoming requests. The vulnerability impacts the ability to protect data handled by the system. The affected API endpoint is not specified. The vulnerable parameter is not specified.
Recommendations Versions prior to 6.4.5 should be updated to version 6.4.5 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2024-08100
CVE-2024-47008
ZDI-24-1324

Affected Products

Ivanti Avalanche