Description
An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 06 May 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 19 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ivanti
Ivanti avalanche |
|
| CPEs | cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ivanti
Ivanti avalanche |
|
| References |
| |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-19T05:08:34.779Z
Reserved: 2024-03-21T01:04:07.089Z
Link: CVE-2024-29848
Updated: 2024-09-19T05:08:34.779Z
Status : Analyzed
Published: 2024-05-31T18:15:12.727
Modified: 2025-05-06T14:43:00.593
Link: CVE-2024-29848
No data.
OpenCVE Enrichment
No data.
Weaknesses