An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory.
History

Tue, 06 May 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Ivanti
Ivanti avalanche
CPEs cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:*
Vendors & Products Ivanti
Ivanti avalanche
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2024-04-19T01:10:11.825Z

Updated: 2024-08-01T23:06:25.127Z

Reserved: 2024-01-18T01:04:07.196Z

Link: CVE-2024-23531

cve-icon Vulnrichment

Updated: 2024-08-01T23:06:25.127Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-19T02:15:07.670

Modified: 2025-05-06T19:23:47.330

Link: CVE-2024-23531

cve-icon Redhat

No data.