CVE-2024-37373: Input Validation
Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37373?
CVE-2024-37373 is considered a critical vulnerability due to its potential for remote code execution by authenticated attackers.
How do I fix CVE-2024-37373?
To resolve CVE-2024-37373, it is recommended to apply the latest security updates provided by Ivanti for the affected versions of Avalanche.
What versions of Ivanti Avalanche are affected by CVE-2024-37373?
CVE-2024-37373 affects Ivanti Avalanche versions 6.3.1, 6.3.2, 6.3.3, 6.3.4, and 6.4.x.
What is the impact of CVE-2024-37373?
The impact of CVE-2024-37373 allows remote authenticated attackers to execute arbitrary code on the affected system.
Who is at risk from CVE-2024-37373?
Organizations using Ivanti Avalanche versions listed in the vulnerability can be at risk if remote authenticated attackers gain access.