Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.
An attacker sends a crafted network request to the skin management component, specifying a path containing path traversal sequences (e.g., '../'). The lack of proper path validation and sanitization allows stepping outside the permitted directory and targeting any file in the system. As a result, the attacker can delete arbitrary files, leading to disruption or complete shutdown of the service.
An unauthenticated attacker can permanently delete arbitrary files on the server, causing denial of service (DoS) and violating system integrity. Loss of critical configuration or system files may prevent the Ivanti Avalanche server from functioning properly.
Ivanti Avalanche should be updated to version 6.4.4 or newer, in accordance with the official security bulletin from the vendor available at the address indicated in the references. Until the patch is deployed, it is recommended to restrict network access to the Ivanti Avalanche management interface only to trusted IP addresses.
Ivanti Avalanche version 6.3.1 (as per the vendor's description; detailed version scope indicated in vendor references)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HIvanti Avalanche
APPIvanti6.3.16.3.1.15076.3.26.3.2.34906.3.36.3.3.1016.3.46.3.4.1536.4.06.4.16.4.1.2076.4.1.2366.4.2
Related vulnerabilities
Buffer overflow w Ivanti Avalanche Manager umożliwiający RCE bez uwierzytelnienia
Heap Overflow w Ivanti Avalanche umożliwia zdalne wykonanie kodu
Heap Overflow w Ivanti Avalanche umożliwiający RCE bez uwierzytelnienia
Heap overflow w Ivanti Avalanche umożliwia zdalne wykonanie kodu
Ivanti Avalanche — RCE/DoS przez korupcję pamięci w Mobile Device Server