CVE-2024-29848

HIGH

Ivanti Avalanche <6.4.x - Command Injection

Title source: llm
STIX 2.1

Description

An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.

Scores

CVSS v3 7.2
EPSS 0.3073
EPSS Percentile 96.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
ivanti/avalanche < 6.4.3.602
Published May 31, 2024
Tracked Since Feb 18, 2026