CVE-2021-30497
Ivanti avalanche Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2021-30497 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can obtain sensitive information via the C:/Windows/system32/config/system.sav value.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 31, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
avalancheBrowse Ivanti / avalanche | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHIvanti Avalanche 6.3.2 - Local File InclusionCVSS 7.5
Ivanti Avalanche 6.3.2 is vulnerable to local file inclusion because it allows remote unauthenticated user to access files that reside outside the 'image' folder.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the affected system.
Remediation
Apply the latest security patches or updates provided by Ivanti to fix the LFI vulnerability in Avalanche 6.3.2.
Source: ProjectDiscovery