Ivanti Avalanche Path Traversal Vulnerability Allowing Authentication Bypass

Vulnerability

A path traversal vulnerability has been identified in Ivanti Avalanche versions prior to 6.4.7. This vulnerability allows remote unauthenticated attackers to bypass authentication. The issue arises from incomplete fixes in a previous vulnerability (CVE-2024-47010).

Impact

Exploitation of this vulnerability allows for authentication bypass, potentially leading to unauthorized access or actions within the application.

Remediation

Users can upgrade to Ivanti Avalanche version 6.4.7 to address this vulnerability. This release is a full product install, and users should perform an in-place upgrade according to the product documentation.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
5.0
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.