
Cloud Vulnerability DB
A community-led vulnerabilities database
A path traversal vulnerability identified as CVE-2024-13180 affects Ivanti Avalanche versions prior to 6.4.7. This vulnerability allows remote unauthenticated attackers to leak sensitive information. Notably, this CVE addresses incomplete fixes from a previous vulnerability (CVE-2024-47011) (NVD).
The vulnerability is classified as a path traversal issue (CWE-22) with a CVSS v3.1 base score of 7.5 (HIGH). The attack vector is network-based (AV:N) with low attack complexity (AC:L), requiring no privileges (PR:N) or user interaction (UI:N). The scope is unchanged (S:U) with high confidentiality impact (C:H) but no impact on integrity (I:N) or availability (A:N) (NVD).
The vulnerability enables unauthorized access to sensitive information through path traversal techniques. The high confidentiality impact rating indicates that attackers can gain access to sensitive data, while system integrity and availability remain unaffected (SecurityWeek).
Ivanti has released version 6.4.7 of Avalanche to address this vulnerability. Organizations are strongly advised to update their Ivanti Avalanche installations to this latest version as soon as possible (ASEC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."