← Back to browse · API

CVE-2024-23535

Severity
HIGH
CVSS
8.8
EPSS
0.68104
Risk score
59.04
CISA KEV
No
PoC
No
Published
2024-04-19
Modified
2025-12-16
First seen
2026-08-07
Aliases
EUVD-2024-21030, GHSA-9FRH-FCFQ-FV6F
Products
Ivanti:Avalanche 6.4.3 <6.4.3
Sources
euvd EUVD-2024-21030

Description

A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

References