Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
avalanche vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2021-42124
An improper access control vulnerability exists in Ivanti Avalanche prior to 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.
Ivanti Avalanche
6.5
CVSSv2
CVE-2021-42126
An improper authorization control vulnerability exists in Ivanti Avalanche prior to 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
Ivanti Avalanche
7.5
CVSSv2
CVE-2021-42127
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche prior to 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
Ivanti Avalanche
7.5
CVSSv2
CVE-2021-42128
An exposed dangerous function vulnerability exists in Ivanti Avalanche prior to 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.
Ivanti Avalanche
7.5
CVSSv2
CVE-2020-12442
Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250.
Ivanti Avalanche 6.3
5
CVSSv2
CVE-2021-30497
Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can o...
Ivanti Avalanche 6.3.2
NA
CVE-2023-41474
Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated malicious user to obtain sensitive information via the javax.faces.resource component.
Ivanti Avalanche 6.3.4.153
1 Github repository
9
CVSSv2
CVE-2020-11733
An issue exists on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metacharacters. The attacker can then, for example, read sensitive files such as appliance adm...
Spirent Avalanche
Spirent Testcenter
NA
CVE-2024-24992
A Path Traversal vulnerability in web component of Ivanti Avalanche prior to 6.4.3 allows a remote authenticated malicious user to execute arbitrary commands as SYSTEM.
NA
CVE-2024-24994
A Path Traversal vulnerability in web component of Ivanti Avalanche prior to 6.4.3 allows a remote authenticated malicious user to execute arbitrary commands as SYSTEM.
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
SSRF
CVE-2023-52162
CVE-2024-23670
CVE-2024-5404
man-in-the-middle
CVE-2024-5214
CVE-2024-4358
CVE-2024-20696
hard-coded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »