7.2

CVE-2024-37373

Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Avalanche Version 6.3.1 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.1.1507 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.2
Ivanti ≫ Avalanche Version 6.3.2 SwPlatform windows
Ivanti ≫ Avalanche Version 6.3.2 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.2.3490
Ivanti ≫ Avalanche Version 6.3.2.3490 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.3
Ivanti ≫ Avalanche Version 6.3.3 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.3.101
Ivanti ≫ Avalanche Version 6.3.3.101 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.4
Ivanti ≫ Avalanche Version 6.3.4 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.4.153 SwEdition premise
Ivanti ≫ Avalanche Version 6.4.0
Ivanti ≫ Avalanche Version 6.4.1
Ivanti ≫ Avalanche Version 6.4.1 SwEdition premise
Ivanti ≫ Avalanche Version 6.4.1.207 SwEdition premise
Ivanti ≫ Avalanche Version 6.4.1.236 SwEdition premise
Ivanti ≫ Avalanche Version 6.4.2 SwEdition premise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.56% 0.72
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
HackerOne 7.2 1.2 5.9
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Avalanche-6-4-4-CVE-2024-38652-CVE-2024-38653-CVE-2024-36136-CVE-2024-37399-CVE-2024-37373
Vendor Advisory