An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory.
Metrics
Affected Vendors & Products
References
History
Tue, 06 May 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ivanti
Ivanti avalanche |
|
CPEs | cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ivanti
Ivanti avalanche |
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: hackerone
Published: 2024-04-19T01:10:11.825Z
Updated: 2024-08-01T23:06:25.127Z
Reserved: 2024-01-18T01:04:07.196Z
Link: CVE-2024-23531

Updated: 2024-08-01T23:06:25.127Z

Status : Analyzed
Published: 2024-04-19T02:15:07.670
Modified: 2025-05-06T19:23:47.330
Link: CVE-2024-23531

No data.