← back
CVE-2024-29848highCWE-434

CVE-2024-29848

33Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.2epss 64%
exploitation probability
64%top 1% of all CVEs
observed exploitation
nono source reports it
An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Ivanti · Avalanche