Vulnerability record · CVE-2024-13179 · published 14 January 2025
CVE-2024-13179: Ivanti Avalanche path traversal allows unauthenticated auth bypass
Ivanti · Avalanche
Ivanti Avalanche before 6.4.7 contains a path traversal flaw (CWE-22) that also enables authentication bypass via an alternate path (CWE-288). A remote, unauthenticated attacker can reach the vulnerable code and bypass authentication, which matters because it exposes the management platform without any credentials.
Description
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with unauthenticated remote network reachability and high EPSS make this a top remediation priority despite no KEV listing.
What it is
Ivanti Avalanche before 6.4.7 contains a path traversal flaw (CWE-22) that also enables authentication bypass via an alternate path (CWE-288). A remote, unauthenticated attacker can reach the vulnerable code and bypass authentication, which matters because it exposes the management platform without any credentials.
Impact
An attacker gains unauthenticated access to the Avalanche management platform, with high confidentiality, integrity and availability impact per the CVSS vector. This can lead to full control of the managed mobile device estate.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/PR:N/UI:N. The description states the attacker is remote and unauthenticated.
Exploitation
Not listed in CISA KEV and no ransomware usage documented. EPSS is high at 0.6296 (99.16th percentile), indicating elevated likelihood of exploitation, but no public exploit reference is included in the record.
What to do
- Upgrade Ivanti Avalanche to version 6.4.7 or later, per the vendor advisory.
- If immediate upgrade is not possible, restrict network access to the Avalanche management interface to trusted hosts only.
- Place the Avalanche server behind a VPN or firewall and block direct internet exposure.
- Monitor Ivanti's advisory page for updated guidance and any hotfixes.
- Review logs for unauthorized access attempts against the Avalanche web interface.
Detection
- Hunt for path traversal patterns such as ../ or encoded variants in HTTP requests to Avalanche endpoints.
- Alert on successful access to Avalanche administrative paths from unauthenticated or unexpected source IPs.
- Baseline normal Avalanche management traffic and flag anomalous requests that bypass login pages.
- Correlate web server logs with authentication logs for requests that reach protected resources without a prior login.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Avalanche-6-4-7-Multiple-CVEs | Vendor Advisory |
Track CVE-2024-13179 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-13179), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.