Vulnerabilities
Vulnerable Software
Ivanti:  >> Avalanche  >> 5.3.1  Security Vulnerabilities
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.
CVSS Score
6.3
EPSS Score
0.021
Published
2023-08-10
Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236
CVSS Score
6.5
EPSS Score
0.021
Published
2023-08-10
A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure.
CVSS Score
7.5
EPSS Score
0.586
Published
2023-05-09
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.
CVSS Score
7.2
EPSS Score
0.847
Published
2023-05-09
An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port.
CVSS Score
7.5
EPSS Score
0.648
Published
2023-03-10
An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.
CVSS Score
8.8
EPSS Score
0.026
Published
2021-12-07
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.
CVSS Score
8.8
EPSS Score
0.816
Published
2021-12-07
An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
CVSS Score
8.8
EPSS Score
0.039
Published
2021-12-07
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
CVSS Score
9.8
EPSS Score
0.68
Published
2021-12-07
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.
CVSS Score
9.8
EPSS Score
0.045
Published
2021-12-07


Contact Us

Shodan ® - All rights reserved