CVE-2024-23532: High severity ivanti avalanche vulnerability
An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. In certain conditions this could also lead to remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23532?
CVE-2024-23532 is considered to have a high severity rating due to its potential to allow denial of service attacks and possibly remote code execution.
How do I fix CVE-2024-23532?
To fix CVE-2024-23532, update Ivanti Avalanche to version 6.4.3 or later, which addresses this vulnerability.
What could happen if CVE-2024-23532 is exploited?
If CVE-2024-23532 is exploited, it could lead to denial of service or remote code execution, posing a significant risk to affected systems.
Who is affected by CVE-2024-23532?
CVE-2024-23532 affects users of Ivanti Avalanche versions prior to 6.4.3.
Is CVE-2024-23532 a zero-day vulnerability?
CVE-2024-23532 is not a zero-day vulnerability as it has been publicly disclosed and a patch is available.