CVE-2024-36136

EUVD-2024-35894
An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
Affected Products (NVD)
VendorProductVersion
ivantiavalanche
6.3.1
ivantiavalanche
6.3.1.1507
ivantiavalanche
6.3.2
ivantiavalanche
6.3.2
ivantiavalanche
6.3.2
ivantiavalanche
6.3.2.3490
ivantiavalanche
6.3.2.3490
ivantiavalanche
6.3.3
ivantiavalanche
6.3.3
ivantiavalanche
6.3.3.101
ivantiavalanche
6.3.3.101
ivantiavalanche
6.3.4
ivantiavalanche
6.3.4
ivantiavalanche
6.3.4.153
ivantiavalanche
6.4.0
ivantiavalanche
6.4.1
ivantiavalanche
6.4.1
ivantiavalanche
6.4.1.207
ivantiavalanche
6.4.1.236
ivantiavalanche
6.4.2
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
ivantiavalanche
6.3.1 ≤
𝑥
< 6.4.4
ADP