CVE-2024-36136: High severity ivanti avalanche vulnerability
Published Aug 14, 2024
·Updated
An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
Affected Software
20 affected components
Ivanti Avalanche=6.3.1
Ivanti Avalanche=6.3.1.1507
Ivanti Avalanche=6.3.2
Ivanti Avalanche Windows=6.3.2
Ivanti Avalanche=6.3.2
Ivanti Avalanche=6.3.2.3490
Ivanti Avalanche=6.3.2.3490
Ivanti Avalanche=6.3.3
Ivanti Avalanche=6.3.3
Ivanti Avalanche=6.3.3.101
Ivanti Avalanche=6.3.3.101
Ivanti Avalanche=6.3.4
Ivanti Avalanche=6.3.4
Ivanti Avalanche=6.3.4.153
Ivanti Avalanche=6.4.0
Ivanti Avalanche=6.4.1
Ivanti Avalanche=6.4.1
Ivanti Avalanche=6.4.1.207
Ivanti Avalanche=6.4.1.236
Ivanti Avalanche=6.4.2
Event History
Aug 14, 2024
CVE Published
via MITRE·02:38 AM
Data Sourced
via MITRE·02:38 AM
DescriptionSeverity
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36136?
CVE-2024-36136 is a denial-of-service vulnerability that allows a remote unauthenticated attacker to crash the WLInfoRailService.
2
How do I fix CVE-2024-36136?
To fix CVE-2024-36136, you should update Ivanti Avalanche to a patched version provided by the vendor.
3
Which versions of Ivanti Avalanche are affected by CVE-2024-36136?
CVE-2024-36136 affects Ivanti Avalanche versions 6.3.1 through 6.4.2.
4
Can CVE-2024-36136 be exploited remotely?
Yes, CVE-2024-36136 can be exploited remotely without authentication.
5
What are the potential impacts of CVE-2024-36136?
The impact of CVE-2024-36136 is that it can lead to service disruptions, resulting in a denial of service.