CVE-2024-13181: Path Traversal
Published Jan 14, 2025
·Updated
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.
Affected Software
1 affected component
Ivanti Avalanche<6.4.6
Event History
Jan 14, 2025
CVE Published
via MITRE·04:53 PM
Data Sourced
via MITRE·04:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13181?
CVE-2024-13181 is classified as a critical severity vulnerability.
2
How do I fix CVE-2024-13181?
To fix CVE-2024-13181, upgrade Ivanti Avalanche to version 6.4.7 or later.
3
What is the impact of CVE-2024-13181?
CVE-2024-13181 allows a remote unauthenticated attacker to bypass authentication, leading to potential unauthorized access.
4
Which versions of Ivanti Avalanche are affected by CVE-2024-13181?
Ivanti Avalanche versions prior to 6.4.7 are affected by CVE-2024-13181.
5
Is CVE-2024-13181 a result of previous vulnerabilities?
Yes, CVE-2024-13181 addresses incomplete fixes from CVE-2024-47010.