Vulnerabilities > Ivanti > Avalanche > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-04-19 CVE-2024-23533 Unspecified vulnerability in Ivanti Avalanche
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information in memory.
network
low complexity
ivanti
6.5
2024-04-19 CVE-2024-24991 Unspecified vulnerability in Ivanti Avalanche
A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.
network
low complexity
ivanti
6.5
2024-04-19 CVE-2024-27978 Unspecified vulnerability in Ivanti Avalanche
A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.
network
low complexity
ivanti
6.5
2024-01-25 CVE-2023-41474 Path Traversal vulnerability in Ivanti Avalanche 6.3.4.153
Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.
network
low complexity
ivanti CWE-22
6.5
2023-05-09 CVE-2023-28125 Race Condition vulnerability in Ivanti Avalanche
An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.
network
high complexity
ivanti CWE-362
5.9
2023-05-09 CVE-2023-28126 Race Condition vulnerability in Ivanti Avalanche
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.
network
high complexity
ivanti CWE-362
5.9
2018-06-29 CVE-2018-8902 Improper Authentication vulnerability in Ivanti Avalanche
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2.
network
low complexity
ivanti CWE-287
6.5