CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It affects Windows, Ivanti. Its EPSS score suggests a 96.6% probability of exploitation in the next 30 days. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
Original NVD Description
Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can obtain sensitive information via the C:/Windows/system32/config/system.sav value.
Related CVEs
Other vulnerabilities affecting the same vendor(s)