← Back to browse · API

CVE-2024-24996

Severity
CRITICAL
CVSS
9.8
EPSS
0.32237
Risk score
50.48
CISA KEV
No
PoC
No
Published
2024-04-19
Modified
2025-03-24
First seen
2026-08-07
Aliases
EUVD-2024-22358, GHSA-HVHJ-8MQF-W2RH
Products
Ivanti:Avalanche, Ivanti:Avalanche 6.4.3 <6.4.3
Sources
euvd EUVD-2024-22358

Description

A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arbitrary commands.

References