CVE-2024-50320
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-50320 is a newly disclosed vulnerability affecting Ivanti Avalanche versions prior to 6.4.6. The issue involves an infinite loop, which when exploited by an unauthenticated attacker, results in a denial of service. The vulnerability allows an attacker to overload the system resources, rendering the Ivanti Avalanche application unresponsive and inaccessible. This can lead to significant downtime and disruption of services for organizations that rely on Ivanti Avalanche for their IT asset management and software delivery. To mitigate this risk, it is recommended that affected organizations upgrade to the latest version of Ivanti Avalanche as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Ivanti Avalanche
Affected Vendors
- Ivanti Software Inc.