CVE-2024-38653
14.08.2024, 03:15
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.Enginsight
Vendor | Product | Version |
---|---|---|
ivanti | avalanche | 6.3.1 |
ivanti | avalanche | 6.3.1.1507 |
ivanti | avalanche | 6.3.2 |
ivanti | avalanche | 6.3.2 |
ivanti | avalanche | 6.3.2 |
ivanti | avalanche | 6.3.2.3490 |
ivanti | avalanche | 6.3.2.3490 |
ivanti | avalanche | 6.3.3 |
ivanti | avalanche | 6.3.3 |
ivanti | avalanche | 6.3.3.101 |
ivanti | avalanche | 6.3.3.101 |
ivanti | avalanche | 6.3.4 |
ivanti | avalanche | 6.3.4 |
ivanti | avalanche | 6.3.4.153 |
ivanti | avalanche | 6.4.0 |
ivanti | avalanche | 6.4.1 |
ivanti | avalanche | 6.4.1 |
ivanti | avalanche | 6.4.1.207 |
ivanti | avalanche | 6.4.1.236 |
ivanti | avalanche | 6.4.2 |
𝑥
= Vulnerable software versions