S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-30497 Scanner

CVE-2021-30497 scanner - Path Traversal vulnerability in Ivanti Avalanche (Premise)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-30497
7.5
CVSS

Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can obtain sensitive information via the C:/Windows/system32/config/system.sav value.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Ivanti Avalanche (Premise) is an enterprise mobility management solution that enables IT teams to manage and secure mobile devices and applications from a single console. It provides comprehensive device and application lifecycle management, including app deployment, updates, and troubleshooting. With Ivanti Avalanche, IT teams can also enforce security policies to meet compliance requirements and protect corporate data.

Recently, a vulnerability with the code CVE-2021-30497 has been detected in Ivanti Avalanche (Premise) 6.3.2. This vulnerability allows remote unauthenticated users to retrieve sensitive information through Absolute Path Traversal. Attackers can exploit this vulnerability by accessing arbitrary files via the imageFilePath parameter processed by the /AvalancheWeb/image endpoint, which is not verified to be within the scope of the image folder. As a result, this can lead to the disclosure of sensitive information, such as system configurations or credentials.

If this vulnerability is exploited, it can lead to serious consequences for businesses. It can expose sensitive information that can be used by attackers to launch more sophisticated attacks, such as identity theft or malware injection. Furthermore, it can also lead to compliance violations, which could result in legal repercussions and reputational damage.

Thanks to the pro features of the s4e.io platform, readers can easily and quickly learn about vulnerabilities in their digital assets. With this platform, businesses can identify and address potential security issues before they can be exploited by attackers. By using this platform, businesses can ensure the security and integrity of their digital assets, while complying with regulatory requirements.

 

REFERENCES

Solution Advice

To protect against this vulnerability, IT teams can take various precautions, including: 

  • Apply the latest security updates and patches for Ivanti Avalanche (Premise).
  • Implement a secure code review process that can identify and fix potential vulnerabilities before deployment.
  • Limit access to Ivanti Avalanche (Premise) to authorized users only.
  • Implement network segmentation to reduce the attack surface.
  • Monitor system logs and network traffic for suspicious activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.