7.5

CVE-2024-38653

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Avalanche Version 6.3.1 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.1.1507 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.2
Ivanti ≫ Avalanche Version 6.3.2 SwPlatform windows
Ivanti ≫ Avalanche Version 6.3.2 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.2.3490
Ivanti ≫ Avalanche Version 6.3.2.3490 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.3
Ivanti ≫ Avalanche Version 6.3.3 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.3.101
Ivanti ≫ Avalanche Version 6.3.3.101 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.4
Ivanti ≫ Avalanche Version 6.3.4 SwEdition premise
Ivanti ≫ Avalanche Version 6.3.4.153 SwEdition premise
Ivanti ≫ Avalanche Version 6.4.0
Ivanti ≫ Avalanche Version 6.4.1
Ivanti ≫ Avalanche Version 6.4.1 SwEdition premise
Ivanti ≫ Avalanche Version 6.4.1.207 SwEdition premise
Ivanti ≫ Avalanche Version 6.4.1.236 SwEdition premise
Ivanti ≫ Avalanche Version 6.4.2 SwEdition premise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 91.98% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
HackerOne 8.2 3.9 4.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Avalanche-6-4-4-CVE-2024-38652-CVE-2024-38653-CVE-2024-36136-CVE-2024-37399-CVE-2024-37373
Vendor Advisory