CVE-2024-38652

Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
hackeroneCNA
8.2 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
ivantiavalanche
6.3.1
ivantiavalanche
6.3.1.1507
ivantiavalanche
6.3.2
ivantiavalanche
6.3.2
ivantiavalanche
6.3.2
ivantiavalanche
6.3.2.3490
ivantiavalanche
6.3.2.3490
ivantiavalanche
6.3.3
ivantiavalanche
6.3.3
ivantiavalanche
6.3.3.101
ivantiavalanche
6.3.3.101
ivantiavalanche
6.3.4
ivantiavalanche
6.3.4
ivantiavalanche
6.3.4.153
ivantiavalanche
6.4.0
ivantiavalanche
6.4.1
ivantiavalanche
6.4.1
ivantiavalanche
6.4.1.207
ivantiavalanche
6.4.1.236
ivantiavalanche
6.4.2
𝑥
= Vulnerable software versions