ZDI-24-1491: Ivanti Avalanche WLAvalancheService TV_FC Infinite Loop Denial-of-Service Vulnerability
Published Nov 13, 2024
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ivanti Avalanche. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-50320.
Affected Software
1 affected component
Ivanti Avalanche
Event History
Nov 13, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-1491?
ZDI-24-1491 has a CVSS rating of 7.5, indicating a high severity level.
2
What type of exploit is associated with ZDI-24-1491?
ZDI-24-1491 allows for a denial-of-service condition to be created by remote attackers.
3
Do attackers need authentication to exploit ZDI-24-1491?
No, authentication is not required to exploit ZDI-24-1491.
4
What software is affected by ZDI-24-1491?
ZDI-24-1491 affects installations of Ivanti Avalanche.
5
How do I mitigate the risks from ZDI-24-1491?
Review current patches and updates for Ivanti Avalanche to address the vulnerability associated with ZDI-24-1491.