PT-2024-8675 · Ivanti · Ivanti Avalanche
Published
2024-08-13
·
Updated
2024-09-04
·
CVE-2024-38653
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Ivanti Avalanche version 6.3.1
Description
The issue is related to an XML External Entity (XXE) flaw in the SmartDeviceServer component of Ivanti Avalanche. This flaw allows a remote unauthenticated attacker to read arbitrary files on the server, potentially disclosing protected information. The vulnerability is associated with incorrect restriction of XML links to external objects.
Recommendations
For Ivanti Avalanche version 6.3.1, consider disabling the
decodeToMap XML External Entity Processing function as a temporary workaround until a patch is available. Restrict access to the SmartDeviceServer component to minimize the risk of exploitation. Avoid using the vulnerable XML processing functionality in the affected server until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Avalanche