← Back to browse · API

CVE-2024-24994

Severity
HIGH
CVSS
8.8
EPSS
0.68104
Risk score
59.04
CISA KEV
No
PoC
No
Published
2024-04-19
Modified
2024-08-01
First seen
2026-08-08
Aliases
EUVD-2024-22356, GHSA-F8VM-C6WX-CC8G
Products
Ivanti:Avalanche, Ivanti:Avalanche 6.4.3 <6.4.3
Sources
euvd EUVD-2024-22356

Description

A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

References