CVE-2024-29848: Ivanti Avalanche

High severity, CVSS 7.2. EPSS: 64.4% chance of exploitation in the next 30 days.

An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.

Affected products

  • Ivanti Avalanche: before 6.4.3.602 (fixed in 6.4.3.602)

Published 2024-05-31. Last modified 2026-06-17.