Vulnerabilities > Ivanti > Avalanche > 5.3

DATE CVE VULNERABILITY TITLE RISK
2024-04-19 CVE-2024-23531 Unspecified vulnerability in Ivanti Avalanche
An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks.
network
low complexity
ivanti
7.5
2024-04-19 CVE-2024-23532 Unspecified vulnerability in Ivanti Avalanche
An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.
network
high complexity
ivanti
7.5
2024-04-19 CVE-2024-23533 Unspecified vulnerability in Ivanti Avalanche
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information in memory.
network
low complexity
ivanti
6.5
2024-04-19 CVE-2024-23534 Unspecified vulnerability in Ivanti Avalanche
An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
network
low complexity
ivanti
8.8
2024-04-19 CVE-2024-23535 Unspecified vulnerability in Ivanti Avalanche
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
network
low complexity
ivanti
8.8
2024-04-19 CVE-2024-24991 Unspecified vulnerability in Ivanti Avalanche
A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.
network
low complexity
ivanti
6.5
2024-04-19 CVE-2024-24992 Unspecified vulnerability in Ivanti Avalanche
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
network
low complexity
ivanti
8.8
2024-04-19 CVE-2024-24993 Unspecified vulnerability in Ivanti Avalanche
A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
network
high complexity
ivanti
7.5
2024-04-19 CVE-2024-24994 Unspecified vulnerability in Ivanti Avalanche
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
network
low complexity
ivanti
8.8
2024-04-19 CVE-2024-24995 Unspecified vulnerability in Ivanti Avalanche
A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
network
high complexity
ivanti
7.5