VYPR
High severity7.5NVD Advisory· Published Apr 19, 2024· Updated Jun 17, 2026

CVE-2024-23531

CVE-2024-23531

Description

An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory.

Affected products

3
  • Ivanti/Avalanchecpe-rescue3 versions
    6.4.3+ 2 more
    • (no CPE)range: 6.4.3
    • cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:*range: <6.4.3.528
    • (no CPE)range: <6.4.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.