Multiple Vulnerabilities Affecting Ivanti Avalanche
Security update includes remediations for 27 vulnerabilities, two of which are critical severity.
Summary
Security update includes remediations for 27 vulnerabilities, two of which are critical severity.
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Ivanti has released a security advisory addressing multiple vulnerabilities in Ivanti Avalanche, two of which are critical severity with a CVSSv3 score of 9.8. Ivanti Avalanche is an mobile device management solution and is used to remotely manage, deploy software, and schedule updates for enterprise mobile devices.
CVE-2024-24996 is a heap overflow vulnerability in the WLInfoRailService component of Ivanti Avalanche which could allow an unauthenticated remote attacker to execute arbitrary commands. Similarly, CVE-2024-29204 is also a heap overflow vulnerability, this time affecting the WLAvalancheService component of Ivanti Avalanche. This could also allow a remote unauthenticated attacker to execute arbitrary commands.
The security advisory also contains 26 additional vulnerabilities at high and medium severities affecting Ivanti Avalanche which include path traversal, out-of-bounds read, and race condition vulnerabilities.
Remediation advice
Affected organisations are advised to review the advisory named "Avalanche 6.4.3 Security Hardening and CVEs addressed" and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 17 April 2024 4:02 pm