CVE-2021-30497

HIGH EXPLOITED NUCLEI

Ivanti Avalanche (Premise) 6.3.2 - Path Traversal

Title source: llm

Description

Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can obtain sensitive information via the C:/Windows/system32/config/system.sav value.

Nuclei Templates (1)

Ivanti Avalanche 6.3.2 - Local File Inclusion
HIGHby gy741

Scores

CVSS v3 7.5
EPSS 0.9267
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2024-01-31
CWE
CWE-22
Status published
Products (1)
ivanti/avalanche 6.3.2
Published Apr 06, 2022
Tracked Since Feb 18, 2026