← back
CVE-2024-23531

CVE-2024-23531

CVSS 7.5 HIGHEPSS 2.4%CWE-190
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 2.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Apr 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
Ivanti · Avalanche

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →