An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
History

Tue, 06 May 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Ivanti
Ivanti avalanche
CPEs cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:*
Vendors & Products Ivanti
Ivanti avalanche
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2024-04-19T01:10:13.138Z

Updated: 2024-08-01T23:06:25.298Z

Reserved: 2024-01-18T01:04:07.196Z

Link: CVE-2024-23528

cve-icon Vulnrichment

Updated: 2024-08-01T23:06:25.298Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-19T02:15:07.207

Modified: 2025-05-06T18:58:45.767

Link: CVE-2024-23528

cve-icon Redhat

No data.