← Back to browse · API

CVE-2024-29848

Severity
HIGH
CVSS
7.2
EPSS
0.64423
Risk score
51.35
CISA KEV
No
PoC
No
Published
2024-05-31
Modified
2024-09-19
First seen
2026-08-07
Aliases
EUVD-2024-26840, GHSA-5H39-X96V-HF62
Products
Ivanti:Avalanche 6.4.3 ≤6.4.3
Sources
euvd EUVD-2024-26840

Description

An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.

References