ZDI-24-1488: Ivanti Avalanche WLAvalancheService TV_FN Null Pointer Dereference Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ivanti Avalanche. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-50317.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1488?
ZDI-24-1488 has been assigned a CVSS rating of 7.5, indicating a high severity level.
How can ZDI-24-1488 be exploited?
ZDI-24-1488 can be exploited by remote attackers to create a denial-of-service condition without requiring authentication.
What software is affected by ZDI-24-1488?
ZDI-24-1488 affects installations of Ivanti Avalanche.
What is the potential impact of ZDI-24-1488?
The impact of ZDI-24-1488 includes the potential for a denial-of-service condition, disrupting service for users.
How do I mitigate ZDI-24-1488?
To mitigate ZDI-24-1488, it is recommended to apply available patches or updates from Ivanti for Avalanche.