Vulnerabilities
Vulnerable Software
Ivanti:  >> Avalanche  >> 6.2  Security Vulnerabilities
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.
CVSS Score
8.8
EPSS Score
0.543
Published
2021-12-07
A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
CVSS Score
8.8
EPSS Score
0.373
Published
2021-12-07
A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
CVSS Score
8.8
EPSS Score
0.517
Published
2021-12-07
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform an arbitrary file write.
CVSS Score
8.1
EPSS Score
0.036
Published
2021-12-07
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. These passwords are stored in the Avalanche databases. This issue only affects customers who have enabled LDAP authentication in their configuration.
CVSS Score
7.8
EPSS Score
0.001
Published
2018-06-29
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to encrypt data. A user with access to system databases can use the discovered key to access potentially confidential stored data, which may include Wi-Fi passwords. This discovered key can be used for all instances of the product.
CVSS Score
6.5
EPSS Score
0.002
Published
2018-06-29


Contact Us

Shodan ® - All rights reserved