An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Mar 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ivanti
Ivanti avalanche |
|
Weaknesses | CWE-125 | |
CPEs | cpe:2.3:a:ivanti:avalanche:6.3.1:*:*:*:premise:*:*:* | |
Vendors & Products |
Ivanti
Ivanti avalanche |
|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: hackerone
Published: 2024-04-24T23:12:51.975Z
Updated: 2025-03-24T19:55:29.993Z
Reserved: 2024-01-18T01:04:07.196Z
Link: CVE-2024-23527

Updated: 2024-08-01T23:06:25.305Z

Status : Awaiting Analysis
Published: 2024-04-25T06:15:54.657
Modified: 2025-03-24T20:15:17.710
Link: CVE-2024-23527

No data.