CVE-2024-37373

Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
hackeroneCNA
7.2 HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
ivantiavalanche
6.3.1
ivantiavalanche
6.3.1.1507
ivantiavalanche
6.3.2
ivantiavalanche
6.3.2
ivantiavalanche
6.3.2
ivantiavalanche
6.3.2.3490
ivantiavalanche
6.3.2.3490
ivantiavalanche
6.3.3
ivantiavalanche
6.3.3
ivantiavalanche
6.3.3.101
ivantiavalanche
6.3.3.101
ivantiavalanche
6.3.4
ivantiavalanche
6.3.4
ivantiavalanche
6.3.4.153
ivantiavalanche
6.4.0
ivantiavalanche
6.4.1
ivantiavalanche
6.4.1
ivantiavalanche
6.4.1.207
ivantiavalanche
6.4.1.236
ivantiavalanche
6.4.2
𝑥
= Vulnerable software versions