← Back to browse · API

CVE-2024-38653

Severity
HIGH
CVSS
8.2
EPSS
0.91984
Risk score
64.99
CISA KEV
No
PoC
No
Published
2024-08-14
Modified
2024-08-14
First seen
2026-08-07
Aliases
EUVD-2024-37508, GHSA-6JJX-98R4-VCM4
Products
Ivanti:Avalanche 6.4.4 <6.4.4
Sources
euvd EUVD-2024-37508

Description

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

References