← Back

CVE-2024-38653

Published: Aug 14, 2024Modified: Aug 15, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

Affected (20)

Products: Ivanti: Avalanche
1 product
Avalanche
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 6.3.1.1507
Version 6.3.1
Version 6.3.2.3490
Version 6.3.2.3490
Version 6.3.2
Version 6.3.2
Version 6.3.2
Version 6.3.3.101
Version 6.3.3.101
Version 6.3.3
Version 6.3.3
Version 6.3.4.153
Version 6.3.4
Version 6.3.4
Version 6.4.0
Version 6.4.1.207
Version 6.4.1.236
Version 6.4.1
Version 6.4.1
Version 6.4.2

Timeline

No history available yet.