CVE-2024-13181
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Jan 14, 2025
CWE ID 288
CWE ID 22
Summary
CVE-2024-13181 is a new vulnerability affecting Ivanti Avalanche before version 6.4.7. This issue involves a path traversal flaw that enables unauthenticated attackers to bypass the authentication process. Notably, this vulnerability builds on the incomplete fixes from the previously identified CVE-2024-47010. By exploiting this path traversal vulnerability, attackers can gain unauthorized access to sensitive information or even take control of affected systems. Ivanti strongly advises users to upgrade to version 6.4.7 or above to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Ivanti Avalanche
Affected Vendors
- Ivanti Software Inc.