CVE-2024-13180: Path Traversal
Published Jan 14, 2025
·Updated
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.
Affected Software
1 affected component
Ivanti Avalanche<6.4.7
Event History
Jan 14, 2025
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13180?
CVE-2024-13180 is classified as a medium severity vulnerability due to its potential for information leakage.
2
How do I fix CVE-2024-13180?
To fix CVE-2024-13180, upgrade Ivanti Avalanche to version 6.4.7 or later as the previous versions are vulnerable.
3
What kind of attack does CVE-2024-13180 enable?
CVE-2024-13180 allows a remote unauthenticated attacker to exploit path traversal and leak sensitive information.
4
Are older versions of Ivanti Avalanche affected by CVE-2024-13180?
Yes, all versions of Ivanti Avalanche before version 6.4.7 are affected by CVE-2024-13180.
5
Is CVE-2024-13180 related to any other vulnerabilities?
Yes, CVE-2024-13180 addresses incomplete fixes from CVE-2024-47011.