Vulnerabilities > Ivanti > Avalanche > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-03 CVE-2023-41726 Incorrect Default Permissions vulnerability in Ivanti Avalanche
Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability
local
low complexity
ivanti CWE-276
7.8
2023-08-10 CVE-2023-32561 Unspecified vulnerability in Ivanti Avalanche
A previously generated artifact by an administrator could be accessed by an attacker.
network
low complexity
ivanti
7.5
2023-05-09 CVE-2023-28127 Path Traversal vulnerability in Ivanti Avalanche
A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure.
network
low complexity
ivanti CWE-22
7.5
2023-05-09 CVE-2023-28128 Unrestricted Upload of File with Dangerous Type vulnerability in Ivanti Avalanche
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.
network
low complexity
ivanti CWE-434
7.2
2023-03-10 CVE-2022-44574 Improper Authentication vulnerability in Ivanti Avalanche
An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port.
network
low complexity
ivanti CWE-287
7.5
2021-12-07 CVE-2021-42127 Deserialization of Untrusted Data vulnerability in Ivanti Avalanche
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
network
low complexity
ivanti CWE-502
7.5
2021-12-07 CVE-2021-42128 Unspecified vulnerability in Ivanti Avalanche
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.
network
low complexity
ivanti
7.5
2020-04-28 CVE-2020-12442 SQL Injection vulnerability in Ivanti Avalanche 6.3
Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250.
network
low complexity
ivanti CWE-89
7.5