Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-36982

This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AgentTaskHandler class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose stored session cookies, leading to further compromise. Was ZDI-CAN-15967.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.9%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2022-36982
  • Ivanti » Avalanche » Version: 6.3.3.101
    cpe:2.3:a:ivanti:avalanche:6.3.3.101


Contact Us

Shodan ® - All rights reserved