Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.
2024-08-14T03:15:05.020
2024-08-15T17:32:39.067
Analyzed
CVSSv3.1: 9.1 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ivanti | avalanche | 6.3.1 | Yes |
Application | ivanti | avalanche | 6.3.1.1507 | Yes |
Application | ivanti | avalanche | 6.3.2 | Yes |
Application | ivanti | avalanche | 6.3.2 | Yes |
Application | ivanti | avalanche | 6.3.2 | Yes |
Application | ivanti | avalanche | 6.3.2.3490 | Yes |
Application | ivanti | avalanche | 6.3.2.3490 | Yes |
Application | ivanti | avalanche | 6.3.3 | Yes |
Application | ivanti | avalanche | 6.3.3 | Yes |
Application | ivanti | avalanche | 6.3.3.101 | Yes |
Application | ivanti | avalanche | 6.3.3.101 | Yes |
Application | ivanti | avalanche | 6.3.4 | Yes |
Application | ivanti | avalanche | 6.3.4 | Yes |
Application | ivanti | avalanche | 6.3.4.153 | Yes |
Application | ivanti | avalanche | 6.4.0 | Yes |
Application | ivanti | avalanche | 6.4.1 | Yes |
Application | ivanti | avalanche | 6.4.1 | Yes |
Application | ivanti | avalanche | 6.4.1.207 | Yes |
Application | ivanti | avalanche | 6.4.1.236 | Yes |
Application | ivanti | avalanche | 6.4.2 | Yes |