Ivanti Avalanche目录遍历漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

# SSD Advisory – Ivanti Avalanche Directory Traversal May 11, 2021 [SSD Disclosure / Technical Lead](https://ssd-disclosure.com/author/noamr/) [Uncategorized](https://ssd-disclosure.com/category/uncategorized/) **TL;DR** Find out how a directory traversal vulnerability in Ivanti Avalanche allows remote unauthenticated user to access files that reside outside the ‘image’ folder. **Vulnerability Summary** Ivanti Avalanche powered by “Wavelink is a mobile device management system. Network security features allow you to manage wireless settings (including encryption and authentication), and apply those settings on a schedule throughout the network. Software distribution features allow you to schedule software distribution to specific devices from the Avalanche Console. Avalanche also provides tools for managing alerts and reports”. A vulnerability in Ivanti Avalanche allows remote unauthenticated users to request files that reside outside the ‘image’ folder. **CVE** Pending...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息