← Vulnerability feed

Vulnerability record · CVE-2024-13179 · published 14 January 2025

CVE-2024-13179: Ivanti Avalanche path traversal allows unauthenticated auth bypass

Ivanti · Avalanche

Ivanti Avalanche before 6.4.7 contains a path traversal flaw (CWE-22) that also enables authentication bypass via an alternate path (CWE-288). A remote, unauthenticated attacker can reach the vulnerable code and bypass authentication, which matters because it exposes the management platform without any credentials.

9.8 CVSS 3.1 Critical EPSS 63% · top 0.8% CWE-22 · Path traversalCWE-288 · Authentication bypass via alternate path
9.8CVSS 3.1 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with unauthenticated remote network reachability and high EPSS make this a top remediation priority despite no KEV listing.

What it is

Ivanti Avalanche before 6.4.7 contains a path traversal flaw (CWE-22) that also enables authentication bypass via an alternate path (CWE-288). A remote, unauthenticated attacker can reach the vulnerable code and bypass authentication, which matters because it exposes the management platform without any credentials.

Impact

An attacker gains unauthenticated access to the Avalanche management platform, with high confidentiality, integrity and availability impact per the CVSS vector. This can lead to full control of the managed mobile device estate.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/PR:N/UI:N. The description states the attacker is remote and unauthenticated.

Exploitation

Not listed in CISA KEV and no ransomware usage documented. EPSS is high at 0.6296 (99.16th percentile), indicating elevated likelihood of exploitation, but no public exploit reference is included in the record.

What to do

  • Upgrade Ivanti Avalanche to version 6.4.7 or later, per the vendor advisory.
  • If immediate upgrade is not possible, restrict network access to the Avalanche management interface to trusted hosts only.
  • Place the Avalanche server behind a VPN or firewall and block direct internet exposure.
  • Monitor Ivanti's advisory page for updated guidance and any hotfixes.
  • Review logs for unauthorized access attempts against the Avalanche web interface.

Detection

  • Hunt for path traversal patterns such as ../ or encoded variants in HTTP requests to Avalanche endpoints.
  • Alert on successful access to Avalanche administrative paths from unauthenticated or unexpected source IPs.
  • Baseline normal Avalanche management traffic and flag anomalous requests that bypass login pages.
  • Correlate web server logs with authentication logs for requests that reach protected resources without a prior login.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-13179 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-38036Ivanti avalanche classic buffer overflow vulnerabilityA security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that …EPSS 2.7%9.8CVE-2024-13181Ivanti avalanche path traversal vulnerabilityPath Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incompl…EPSS 32%9.8CVE-2024-47010Ivanti avalanche path traversal vulnerabilityPath Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.EPSS 38%9.8CVE-2024-47009Ivanti avalanche path traversal vulnerabilityPath Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.EPSS 1.7%9.8CVE-2024-29204Ivanti avalanche heap-based buffer overflow vulnerabilityA Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute ar…EPSS 4.3%9.8CVE-2024-24996Ivanti avalanche heap-based buffer overflow vulnerabilityA Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute ar…EPSS 32%9.8CVE-2024-22061Ivanti avalanche command injection vulnerabilityA Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arb…EPSS 3.6%9.8CVE-2023-46261Ivanti avalanche out-of-bounds write vulnerabilityAn attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2024-13179), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.