CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-38652

CVSS 9.1v3.1pub. 2024-08-14upd. 2024-08-15

Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.

🤖 AI Analysis
How it works

An attacker sends a crafted network request to the skin management component, specifying a path containing path traversal sequences (e.g., '../'). The lack of proper path validation and sanitization allows stepping outside the permitted directory and targeting any file in the system. As a result, the attacker can delete arbitrary files, leading to disruption or complete shutdown of the service.

Impact

An unauthenticated attacker can permanently delete arbitrary files on the server, causing denial of service (DoS) and violating system integrity. Loss of critical configuration or system files may prevent the Ivanti Avalanche server from functioning properly.

Mitigation & patch

Ivanti Avalanche should be updated to version 6.4.4 or newer, in accordance with the official security bulletin from the vendor available at the address indicated in the references. Until the patch is deployed, it is recommended to restrict network access to the Ivanti Avalanche management interface only to trusted IP addresses.

Who is affected

Ivanti Avalanche version 6.3.1 (as per the vendor's description; detailed version scope indicated in vendor references)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Ivanti Avalanche

    APP
    Ivanti
    6.3.16.3.1.15076.3.26.3.2.34906.3.36.3.3.1016.3.46.3.4.1536.4.06.4.16.4.1.2076.4.1.2366.4.2
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path TraversalAuth BypassDoS
CWE
References

Related vulnerabilities

CVE-2023-38036CRITICAL9.8PL ✓same product

Buffer overflow w Ivanti Avalanche Manager umożliwiający RCE bez uwierzytelnienia

CVE-2024-29204CRITICAL9.8PL ✓same product

Heap Overflow w Ivanti Avalanche umożliwia zdalne wykonanie kodu

CVE-2024-22061CRITICAL9.8PL ✓same product

Heap Overflow w Ivanti Avalanche umożliwiający RCE bez uwierzytelnienia

CVE-2024-24996CRITICAL9.8PL ✓same product

Heap overflow w Ivanti Avalanche umożliwia zdalne wykonanie kodu

CVE-2023-46216CRITICAL9.8PL ✓same product

Ivanti Avalanche — RCE/DoS przez korupcję pamięci w Mobile Device Server