CVE-2024-23526: High severity ivanti avalanche vulnerability
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23526?
CVE-2024-23526 is classified as a medium severity vulnerability due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2024-23526?
To mitigate CVE-2024-23526, update Ivanti Avalanche to version 6.4.3 or later where the vulnerability is addressed.
What does the CVE-2024-23526 vulnerability affect?
CVE-2024-23526 affects the WLAvalancheService component of Ivanti Avalanche versions prior to 6.4.3.
Who can exploit CVE-2024-23526?
CVE-2024-23526 can be exploited by unauthenticated remote attackers under certain conditions.
What kind of information can be accessed through CVE-2024-23526?
CVE-2024-23526 allows attackers to read sensitive information stored in memory, which could lead to data leakage.