Ivanti Avalanche 6.4.1.236 Premise Edition

CPE Details

Ivanti Avalanche 6.4.1.236 Premise Edition
6.4.1.236
2023-11-08
15h38 +00:00
2023-11-08
15h38 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ivanti:avalanche:6.4.1.236:*:*:*:premise:*:*:*

Informations

Vendor

ivanti

Product

avalanche

Version

6.4.1.236

Software Edition

premise

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-13181 2025-01-14 16h53 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.
9.8
Critical
CVE-2024-13180 2025-01-14 16h52 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.
7.5
High
CVE-2024-13179 2025-01-14 16h51 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.
9.8
Critical
CVE-2024-50331 2024-11-12 15h34 +00:00 An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.
7.5
High
CVE-2024-50321 2024-11-12 15h33 +00:00 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
High
CVE-2024-50320 2024-11-12 15h32 +00:00 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
High
CVE-2024-50319 2024-11-12 15h32 +00:00 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
High
CVE-2024-50318 2024-11-12 15h30 +00:00 A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
High
CVE-2024-50317 2024-11-12 15h29 +00:00 A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
7.5
High
CVE-2024-47011 2024-10-08 16h30 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
7.5
High
CVE-2024-47010 2024-10-08 16h29 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
9.8
Critical
CVE-2024-47009 2024-10-08 16h28 +00:00 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
9.8
Critical
CVE-2024-47008 2024-10-08 16h28 +00:00 Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.
7.5
High
CVE-2024-47007 2024-10-08 16h27 +00:00 A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.
7.5
High
CVE-2024-38652 2024-08-14 02h38 +00:00 Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.
9.1
Critical
CVE-2024-37373 2024-08-14 02h38 +00:00 Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
7.2
High
CVE-2024-37399 2024-08-14 02h38 +00:00 A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
7.5
High
CVE-2024-38653 2024-08-14 02h38 +00:00 XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
7.5
High
CVE-2024-36136 2024-08-14 02h38 +00:00 An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
7.5
High
CVE-2024-29848 2024-05-31 17h38 +00:00 An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.
7.2
High
CVE-2024-23527 2024-04-24 23h12 +00:00 An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
7.5
High
CVE-2024-23526 2024-04-19 01h10 +00:00 An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
7.5
High
CVE-2024-22061 2024-04-19 01h10 +00:00 A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands
9.8
Critical
CVE-2024-23529 2024-04-19 01h10 +00:00 An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
7.5
High
CVE-2024-23528 2024-04-19 01h10 +00:00 An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
7.5
High
CVE-2024-25000 2024-04-19 01h10 +00:00 A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
8.8
High
CVE-2024-27977 2024-04-19 01h10 +00:00 A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete arbitrary files, thereby leading to Denial-of-Service.
8.1
High
CVE-2024-24992 2024-04-19 01h10 +00:00 A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
8.8
High
CVE-2024-23532 2024-04-19 01h10 +00:00 An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. In certain conditions this could also lead to remote code execution.
7.5
High
CVE-2024-23535 2024-04-19 01h10 +00:00 A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
8.8
High
CVE-2024-24998 2024-04-19 01h10 +00:00 A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
8.8
High
CVE-2024-24995 2024-04-19 01h10 +00:00 A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
7.5
High
CVE-2024-24993 2024-04-19 01h10 +00:00 A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
7.5
High
CVE-2024-24999 2024-04-19 01h10 +00:00 A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
8.8
High
CVE-2024-24991 2024-04-19 01h10 +00:00 A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.
6.5
Medium
CVE-2024-24997 2024-04-19 01h10 +00:00 A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
8.8
High
CVE-2024-27978 2024-04-19 01h10 +00:00 A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.
6.5
Medium
CVE-2024-24994 2024-04-19 01h10 +00:00 A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
8.8
High
CVE-2024-24996 2024-04-19 01h10 +00:00 A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arbitrary commands.
9.8
Critical
CVE-2024-23534 2024-04-19 01h10 +00:00 An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
8.8
High
CVE-2024-23533 2024-04-19 01h10 +00:00 An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information in memory.
6.5
Medium
CVE-2024-23531 2024-04-19 01h10 +00:00 An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory.
7.5
High
CVE-2024-23530 2024-04-19 01h10 +00:00 An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
7.5
High
CVE-2024-27976 2024-04-19 01h10 +00:00 A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
8.8
High
CVE-2024-29204 2024-04-19 01h10 +00:00 A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands
9.8
Critical
CVE-2024-27975 2024-04-19 01h10 +00:00 An Use-after-free vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
8.8
High
CVE-2024-27984 2024-04-19 01h10 +00:00 A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete specific type of files and/or cause denial of service.
7.1
High
CVE-2023-46220 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2023-46261 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2023-46260 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2023-46258 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2023-46803 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).
7.5
High
CVE-2023-46264 2023-12-19 15h43 +00:00 An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
9.8
Critical
CVE-2023-46224 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2023-46221 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2023-46216 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2023-46222 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2023-41727 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2023-46217 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2023-46257 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2023-46804 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).
7.5
High
CVE-2023-46263 2023-12-19 15h43 +00:00 An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.
9.8
Critical
CVE-2023-46225 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2023-46259 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2023-46223 2023-12-19 15h43 +00:00 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
9.8
Critical
CVE-2021-22962 2023-12-19 15h43 +00:00 An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
9.1
Critical