CVE-2024-38653
80Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 8.2epss 92%
from disclosure to weapon
Published on NVDAug 14
VulnCheck+120d
exploitation probability
92%top 1% of all CVEs
observed exploitation
yesVulnCheck
In short
A flaw in Ivanti Avalanche 6.3.1 allows attackers to read any file on the server by sending specially crafted XML requests, without needing to log in. This can expose sensitive data like configuration files or credentials.
Technical detail
XXE (XML External Entity) injection vulnerability in SmartDeviceServer component allows unauthenticated remote attackers to read arbitrary files via malicious XML payloads. Exploitation requires network access to the affected endpoint and no authentication; successful exploitation results in information disclosure of sensitive server files.
Summary generated and translated by AI from the official description.
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Affected products
Ivanti · Avalanche