Ivanti Avalanche Path Traversal Vulnerability Allowing Authentication Bypass

Vulnerability

A path traversal vulnerability has been identified in Ivanti Avalanche versions prior to 6.4.7. This vulnerability allows remote unauthenticated attackers to bypass authentication, addressing incomplete fixes from a previous vulnerability (CVE-2024-47010).

Impact

Exploitation of this vulnerability allows for authentication bypass, potentially leading to unauthorized access or actions within the application.

Remediation

Users can upgrade to Ivanti Avalanche version 6.4.7. This release is a full product install, and an in-place upgrade can be performed according to the product documentation.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
5.0
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.