CVE-2024-47009: Path Traversal
Published Oct 8, 2024
·Updated
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
Affected Software
1 affected component
Ivanti Avalanche<6.4.5
Event History
Oct 8, 2024
CVE Published
via MITRE·04:28 PM
Data Sourced
via MITRE·04:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47009?
CVE-2024-47009 is categorized as a high severity vulnerability due to its ability to allow remote unauthenticated attackers to bypass authentication.
2
What impact does CVE-2024-47009 have on Ivanti Avalanche?
CVE-2024-47009 permits attackers to exploit path traversal, potentially leading to unauthorized access to sensitive data.
3
How do I fix CVE-2024-47009?
To resolve CVE-2024-47009, upgrade Ivanti Avalanche to version 6.4.5 or later.
4
Can CVE-2024-47009 be exploited remotely?
Yes, CVE-2024-47009 can be exploited remotely without authentication by an attacker.
5
Which versions of Ivanti Avalanche are affected by CVE-2024-47009?
CVE-2024-47009 affects all versions of Ivanti Avalanche before 6.4.5.