VYPR
High severity7.5NVD Advisory· Published Apr 19, 2024· Updated Jun 17, 2026

CVE-2024-23532

CVE-2024-23532

Description

An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. In certain conditions this could also lead to remote code execution.

Affected products

3
  • Ivanti/Avalanchecpe-rescue3 versions
    6.4.3+ 2 more
    • (no CPE)range: 6.4.3
    • cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:*range: <6.4.3.528
    • (no CPE)range: <6.4.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.