CVE-2021-42128

CRITICAL

Ivanti Avalanche < 6.3.3 - Privilege Escalation

Title source: rule
STIX 2.1

Description

An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.

Scores

CVSS v3 9.8
EPSS 0.1689
EPSS Percentile 95.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-749
Status published
Products (1)
ivanti/avalanche < 6.3.3
Published Dec 07, 2021
Tracked Since Feb 18, 2026