VDB
CVE-2024-38653
CVE-2024-38653
PUBLISHED
Es besteht eine Schwachstelle in Ivanti Avalanche. Diese Fehler betrifft die Komponente SmartDeviceServer aufgrund einer XML External Entity (XXE) Injection. Ein entfernter, anonymer Angreifer kann diese Sicherheitslücke ausnutzen, um beliebige Dateien auf dem Server zu lesen.
EPSS 90.73% · 99.6th percentile
Risk Scores
EPSS Score
90.73%
99.6th percentile
Timeline
- Aug 13, 2024 CVE Published
- Aug 14, 2024 EPSS Score
- Aug 14, 2024 PoC Published
- Aug 26, 2024 EPSS Score
- Sep 8, 2024 PoC Published
- Oct 4, 2024 Coalition ESS Score
- Nov 20, 2024 EPSS Score
- Nov 21, 2024 EPSS Score
- Dec 15, 2024 PoC Published
- Dec 20, 2024 PoC Published
- Feb 4, 2025 PoC Published
- Feb 11, 2025 PoC Published
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1846.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1846 advisory
- https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Avalanche-6-4-4-CVE-2024-38652-CVE-2024-38653-CVE-2024-36136-CVE-2024-37399-CVE-2024-37373 advisory