An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information in memory.
History

Tue, 06 May 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Ivanti
Ivanti avalanche
CPEs cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:*
Vendors & Products Ivanti
Ivanti avalanche
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2024-04-19T01:10:11.827Z

Updated: 2024-08-01T23:06:25.130Z

Reserved: 2024-01-18T01:04:07.197Z

Link: CVE-2024-23533

cve-icon Vulnrichment

Updated: 2024-08-01T23:06:25.130Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-19T02:15:07.980

Modified: 2025-05-06T19:24:55.380

Link: CVE-2024-23533

cve-icon Redhat

No data.