ZDI-CAN-25713: ZDI-25-044: Ivanti Avalanche SecureFilter Authentication Bypass Vulnerability
This vulnerability allows remote attackers to partially bypass authentication on affected installations of Ivanti Avalanche. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2024-13179.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25713?
The vulnerability ZDI-CAN-25713 is rated with a CVSS score of 7.3, indicating it has a high severity.
How do I fix ZDI-CAN-25713?
To fix ZDI-CAN-25713, apply the latest security patches provided by Ivanti for the Avalanche product.
What type of attacks can exploit ZDI-CAN-25713?
ZDI-CAN-25713 can be exploited by remote attackers to partially bypass authentication without the need for credentials.
Which software versions are affected by ZDI-CAN-25713?
ZDI-CAN-25713 affects installations of Ivanti Avalanche, but specific version numbers are not disclosed.
Is authentication required to exploit ZDI-CAN-25713?
No, authentication is not required to exploit the vulnerability ZDI-CAN-25713.