CVE-2024-23531: Ivanti Avalanche

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory.

Affected products

  • Ivanti Avalanche: before 6.4.3.528 (fixed in 6.4.3.528)

Published 2024-04-19. Last modified 2026-06-17.