← Back

CVE-2024-29848

nvd nist
Published: May 31, 2024Modified: May 6, 2025

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.

Affected (1)

Products: Ivanti: Avalanche
1 product
Avalanche
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.4.3.602

References (4)

Timeline

No history available yet.