CVE-2024-13181

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 288
CWE ID 22

Summary

CVE-2024-13181 is a new vulnerability affecting Ivanti Avalanche before version 6.4.7. This issue involves a path traversal flaw that enables unauthenticated attackers to bypass the authentication process. Notably, this vulnerability builds on the incomplete fixes from the previously identified CVE-2024-47010. By exploiting this path traversal vulnerability, attackers can gain unauthorized access to sensitive information or even take control of affected systems. Ivanti strongly advises users to upgrade to version 6.4.7 or above to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ivanti Avalanche

Affected Vendors

  • Ivanti Software Inc.