📦 Avalanche

by Ivanti

🔍 What is Avalanche?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-38036

CRITICAL CVSS 9.8 Jul 12, 2025

This is a critical buffer overflow vulnerability in Ivanti Avalanche Manager that allows unauthenticated attackers to potentially execute arbitrary code or cause service disruption. It affects all Iva...

CVE-2024-38652

CRITICAL CVSS 9.1 Aug 14, 2024

This vulnerability allows remote unauthenticated attackers to delete arbitrary files on Ivanti Avalanche servers through path traversal in the skin management component. This can lead to denial of ser...

CVE-2024-29204

CRITICAL CVSS 9.8 Apr 19, 2024

A heap overflow vulnerability in the WLAvalancheService component of Ivanti Avalanche allows remote unauthenticated attackers to execute arbitrary commands. This affects Ivanti Avalanche versions befo...

CVE-2024-24996

CRITICAL CVSS 9.8 Apr 19, 2024

This is a critical heap overflow vulnerability in Ivanti Avalanche's WLInfoRailService component that allows unauthenticated remote attackers to execute arbitrary commands on affected systems. It affe...

CVE-2024-22061

CRITICAL CVSS 9.8 Apr 19, 2024

A heap overflow vulnerability in the WLInfoRailService component of Ivanti Avalanche allows remote unauthenticated attackers to execute arbitrary commands on affected systems. This affects Ivanti Aval...

CVE-2023-46261

CRITICAL CVSS 9.8 Dec 19, 2023

This critical vulnerability in the Mobile Device Server allows attackers to send specially crafted data packets that cause memory corruption, potentially leading to denial of service or remote code ex...

CVE-2023-46263

CRITICAL CVSS 9.8 Dec 19, 2023

This vulnerability allows attackers to upload malicious files to Avalanche systems, leading to remote code execution. It affects Avalanche versions 6.4.1 and below, putting organizations using this en...

CVE-2023-46265

CRITICAL CVSS 9.8 Dec 19, 2023

This critical vulnerability allows unauthenticated attackers to exploit an XML External Entity (XXE) vulnerability in the Smart Device Server, potentially leading to data leakage or Server-Side Reques...

CVE-2023-46224

CRITICAL CVSS 9.8 Dec 19, 2023

This critical vulnerability in the Mobile Device Server allows attackers to send specially crafted packets that cause memory corruption, potentially leading to remote code execution or denial of servi...

CVE-2023-46257

CRITICAL CVSS 9.8 Dec 19, 2023

This critical vulnerability in Mobile Device Server allows remote attackers to send specially crafted packets that cause memory corruption, potentially leading to denial of service or remote code exec...

CVE-2023-46259

CRITICAL CVSS 9.8 Dec 19, 2023

CVE-2023-46259 is a critical memory corruption vulnerability in the Mobile Device Server component of Ivanti Avalanche. Attackers can send specially crafted packets to trigger memory corruption, poten...

CVE-2023-46216

CRITICAL CVSS 9.8 Dec 19, 2023

CVE-2023-46216 is a critical memory corruption vulnerability in the Mobile Device Server component of Ivanti Avalanche. Attackers can send specially crafted packets to trigger denial of service or pot...

CVE-2023-46220

CRITICAL CVSS 9.8 Dec 19, 2023

This critical vulnerability in the Mobile Device Server allows attackers to send specially crafted packets that cause memory corruption, potentially leading to denial of service or remote code executi...

CVE-2023-46222

CRITICAL CVSS 9.8 Dec 19, 2023

This critical vulnerability in the Mobile Device Server allows attackers to send specially crafted packets that cause memory corruption, potentially leading to remote code execution or denial of servi...

CVE-2023-41727

CRITICAL CVSS 9.8 Dec 19, 2023

This critical vulnerability in the Mobile Device Server allows attackers to send specially crafted packets that cause memory corruption, potentially leading to remote code execution or denial of servi...

CVE-2021-22962

CRITICAL CVSS 9.1 Dec 19, 2023

CVE-2021-22962 is a vulnerability in Ivanti Avalanche that allows attackers to send specially crafted requests leading to sensitive data leakage or resource-based denial-of-service attacks. This affec...

CVE-2023-32560

CRITICAL CVSS 9.8 Aug 10, 2023

This vulnerability in Wavelink Avalanche Manager allows an attacker to send a specially crafted message, potentially leading to service disruption or arbitrary code execution. It affects systems runni...

CVE-2023-32562

CRITICAL CVSS 9.8 Aug 10, 2023

This vulnerability allows attackers to upload malicious files to Avalanche systems, leading to remote code execution. It affects all Avalanche versions 6.3.x and below. Attackers can compromise the en...

CVE-2023-32564

CRITICAL CVSS 9.8 Aug 10, 2023

This vulnerability allows attackers to upload malicious files to Avalanche systems, leading to remote code execution. It affects Ivanti Avalanche versions 6.4.1 and earlier. Attackers can potentially ...

CVE-2023-32566

CRITICAL CVSS 9.1 Aug 10, 2023

CVE-2023-32566 is a vulnerability in Ivanti Avalanche that allows attackers to send specially crafted requests leading to sensitive data leakage or resource-based denial-of-service attacks. This affec...

CVE-2025-8296

HIGH CVSS 7.2 Aug 12, 2025

This SQL injection vulnerability in Ivanti Avalanche allows authenticated admin users to execute arbitrary SQL queries, potentially leading to remote code execution. Organizations using Ivanti Avalanc...

CVE-2024-13180

HIGH CVSS 7.5 Jan 14, 2025

CVE-2024-13180 is a path traversal vulnerability in Ivanti Avalanche that allows remote unauthenticated attackers to access sensitive files and information. This affects Ivanti Avalanche versions befo...

CVE-2024-13181

HIGH CVSS 7.3 Jan 14, 2025

CVE-2024-13181 is a path traversal vulnerability in Ivanti Avalanche that allows remote unauthenticated attackers to bypass authentication mechanisms. This affects Ivanti Avalanche versions before 6.4...

CVE-2024-50321

HIGH CVSS 7.5 Nov 12, 2024

An infinite loop vulnerability in Ivanti Avalanche allows remote unauthenticated attackers to cause denial of service by crashing the service. This affects all Ivanti Avalanche installations before ve...

CVE-2024-50317

HIGH CVSS 7.5 Nov 12, 2024

A null pointer dereference vulnerability in Ivanti Avalanche allows remote unauthenticated attackers to crash the service, causing denial of service. This affects all Ivanti Avalanche installations be...

CVE-2024-50319

HIGH CVSS 7.5 Nov 12, 2024

CVE-2024-50319 is an infinite loop vulnerability in Ivanti Avalanche that allows remote unauthenticated attackers to cause denial of service by crashing the service. This affects all Ivanti Avalanche ...

CVE-2024-47010

HIGH CVSS 7.3 Oct 8, 2024

CVE-2024-47010 is a path traversal vulnerability in Ivanti Avalanche that allows remote unauthenticated attackers to bypass authentication mechanisms. This affects all Ivanti Avalanche installations b...

CVE-2024-47008

HIGH CVSS 7.5 Oct 8, 2024

This Server-Side Request Forgery (SSRF) vulnerability in Ivanti Avalanche allows remote unauthenticated attackers to make the server send requests to internal systems, potentially exposing sensitive i...

CVE-2024-36136

HIGH CVSS 7.5 Aug 14, 2024

An off-by-one error in WLInfoRailService in Ivanti Avalanche allows remote unauthenticated attackers to crash the service, causing denial of service. This affects Ivanti Avalanche 6.3.1 installations,...

CVE-2024-37399

HIGH CVSS 7.5 Aug 14, 2024

This vulnerability allows remote unauthenticated attackers to cause a denial of service (DoS) by crashing the WLAvalancheService in Ivanti Avalanche. The NULL pointer dereference can be triggered with...

CVE-2024-29848

HIGH CVSS 7.2 May 31, 2024

This vulnerability allows authenticated privileged users in Ivanti Avalanche to upload arbitrary files, leading to remote code execution with SYSTEM privileges. It affects Ivanti Avalanche web compone...

CVE-2024-27976

HIGH CVSS 8.8 Apr 19, 2024

This path traversal vulnerability in Ivanti Avalanche's web component allows authenticated remote attackers to execute arbitrary commands with SYSTEM privileges. It affects Ivanti Avalanche versions b...

CVE-2024-27984

HIGH CVSS 7.1 Apr 19, 2024

This path traversal vulnerability in Ivanti Avalanche's web component allows authenticated remote attackers to delete specific files or cause denial of service. It affects Ivanti Avalanche versions be...

CVE-2024-24998

HIGH CVSS 8.8 Apr 19, 2024

This path traversal vulnerability in Ivanti Avalanche allows authenticated remote attackers to execute arbitrary commands with SYSTEM privileges. It affects Ivanti Avalanche versions before 6.4.3. Att...

CVE-2024-25000

HIGH CVSS 8.8 Apr 19, 2024

This path traversal vulnerability in Ivanti Avalanche's web component allows authenticated remote attackers to execute arbitrary commands with SYSTEM privileges. It affects Ivanti Avalanche versions b...

CVE-2024-23534

HIGH CVSS 8.8 Apr 19, 2024

This vulnerability allows authenticated remote attackers to upload malicious files to Ivanti Avalanche web components, leading to arbitrary command execution with SYSTEM privileges. It affects Ivanti ...

CVE-2024-24992

HIGH CVSS 8.8 Apr 19, 2024

This path traversal vulnerability in Ivanti Avalanche allows authenticated remote attackers to execute arbitrary commands with SYSTEM privileges. It affects Ivanti Avalanche versions before 6.4.3. Att...

CVE-2024-24994

HIGH CVSS 8.8 Apr 19, 2024

This path traversal vulnerability in Ivanti Avalanche allows authenticated remote attackers to execute arbitrary commands with SYSTEM privileges. It affects Ivanti Avalanche versions before 6.4.3. Att...

CVE-2024-23528

HIGH CVSS 7.5 Apr 19, 2024

An out-of-bounds read vulnerability in Ivanti Avalanche's WLAvalancheService component allows unauthenticated remote attackers to read sensitive information from memory. This affects Ivanti Avalanche ...

CVE-2024-23530

HIGH CVSS 7.5 Apr 19, 2024

An unauthenticated remote attacker can exploit an out-of-bounds read vulnerability in Ivanti Avalanche's WLAvalancheService component to read sensitive information from memory. This affects Ivanti Ava...

CVE-2024-23532

HIGH CVSS 7.5 Apr 19, 2024

An authenticated remote attacker can exploit an out-of-bounds read vulnerability in the WLAvalancheService component of Ivanti Avalanche to cause denial of service. In some conditions, this may also l...

CVE-2023-46803

HIGH CVSS 7.5 Dec 19, 2023

This vulnerability allows attackers to send specially crafted data packets to the Mobile Device Server, causing memory corruption that can lead to Denial of Service (DoS). Organizations using Ivanti A...

CVE-2023-41726

HIGH CVSS 7.8 Nov 3, 2023

CVE-2023-41726 is a local privilege escalation vulnerability in Ivanti Avalanche caused by incorrect default permissions. An authenticated local attacker can exploit this to gain SYSTEM/root privilege...

CVE-2022-43554

HIGH CVSS 7.8 Nov 3, 2023

CVE-2022-43554 is a local privilege escalation vulnerability in Ivanti Avalanche Smart Device Service where missing authentication allows local attackers to execute arbitrary code with SYSTEM privileg...

CVE-2023-28127

HIGH CVSS 7.5 May 9, 2023

This path traversal vulnerability in Ivanti Avalanche allows attackers to access arbitrary files on the server by manipulating file path parameters. It affects all Avalanche versions 6.3.x and below, ...

CVE-2022-36980

HIGH CVSS 8.1 Mar 29, 2023

This authentication bypass vulnerability in Ivanti Avalanche allows remote attackers to gain unauthorized access to the EnterpriseServer service. Attackers with existing authentication credentials can...

CVE-2022-36971

HIGH CVSS 8.8 Mar 29, 2023

This vulnerability in Ivanti Avalanche allows authenticated remote attackers to bypass authentication mechanisms and execute arbitrary code via insecure deserialization in the JwtTokenUtility class. A...

CVE-2021-30497

HIGH CVSS 7.5 Apr 6, 2022

CVE-2021-30497 is an absolute path traversal vulnerability in Ivanti Avalanche (Premise) that allows unauthenticated remote attackers to read arbitrary files on the server. The vulnerability exists in...

CVE-2021-42124

HIGH CVSS 8.8 Dec 7, 2021

This vulnerability allows an attacker with access to the Inforail Service in Ivanti Avalanche to perform session takeover, potentially gaining unauthorized access to the system. It affects Ivanti Aval...

CVE-2021-42126

HIGH CVSS 8.8 Dec 7, 2021

This vulnerability allows an attacker with access to the Inforail Service in Ivanti Avalanche to escalate privileges, potentially gaining administrative control. It affects Ivanti Avalanche users runn...

CVE-2021-42129

HIGH CVSS 8.8 Dec 7, 2021

This command injection vulnerability in Ivanti Avalanche allows attackers with access to the Inforail Service to execute arbitrary commands on the system. Organizations running Ivanti Avalanche versio...

CVE-2021-42131

HIGH CVSS 8.8 Dec 7, 2021

This SQL injection vulnerability in Ivanti Avalanche allows attackers with access to the Inforail Service to execute arbitrary SQL commands, potentially leading to privilege escalation. It affects Iva...

CVE-2021-42133

HIGH CVSS 8.1 Dec 7, 2021

This vulnerability in Ivanti Avalanche allows attackers with access to the Inforail Service to write arbitrary files to the system. This could lead to remote code execution, data manipulation, or syst...