Record summary

CVE-2021-30497 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can obtain sensitive information via the C:/Windows/system32/config/system.sav value.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 31, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHIvanti Avalanche 6.3.2 - Local File InclusionCVSS 7.5

Ivanti Avalanche 6.3.2 is vulnerable to local file inclusion because it allows remote unauthenticated user to access files that reside outside the 'image' folder.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the affected system.

Remediation

Apply the latest security patches or updates provided by Ivanti to fix the LFI vulnerability in Avalanche 6.3.2.

WeaknessesCWE-22
Authorsgy741
Template tagscve2021cveavalanchetraversallfiivantiwindowsvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:ivanti:avalanche:6.3.2:*:*:*:*:windows:*:*

Source: ProjectDiscovery

References

4