Vulnerabilities > Ivanti > Avalanche
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-03-29 | CVE-2022-36983 | Unspecified vulnerability in Ivanti Avalanche 6.3.3.101 This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. | 9.8 |
2023-03-10 | CVE-2022-44574 | Improper Authentication vulnerability in Ivanti Avalanche An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port. | 7.5 |
2022-04-06 | CVE-2021-30497 | Path Traversal vulnerability in Ivanti Avalanche 6.3.2 Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. | 7.5 |
2021-12-07 | CVE-2021-42124 | Unspecified vulnerability in Ivanti Avalanche An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover. | 8.8 |
2021-12-07 | CVE-2021-42125 | Unrestricted Upload of File with Dangerous Type vulnerability in Ivanti Avalanche An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files. | 8.8 |
2021-12-07 | CVE-2021-42126 | Unspecified vulnerability in Ivanti Avalanche An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation. | 8.8 |
2021-12-07 | CVE-2021-42127 | Deserialization of Untrusted Data vulnerability in Ivanti Avalanche A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service. | 9.8 |
2021-12-07 | CVE-2021-42128 | Unspecified vulnerability in Ivanti Avalanche An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service. | 9.8 |
2021-12-07 | CVE-2021-42129 | Command Injection vulnerability in Ivanti Avalanche A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution. | 8.8 |
2021-12-07 | CVE-2021-42130 | Deserialization of Untrusted Data vulnerability in Ivanti Avalanche A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution. | 8.8 |