S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Nov 20, 2024

CVE-2024-38653 Scanner

CVE-2024-38653 scanner - XML External Entity (XXE) vulnerability in Ivanti Avalanche SmartDeviceServer

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-38653
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Avalancheby Ivanti
AFFECTED< 6.4.4SAFE ✓≥ 6.4.4
avalancheby ivanti
AFFECTED< 6.4.4SAFE ✓≥ 6.4.4
Updated Aug 22, 2026View on NVD →
Detail

Ivanti Avalanche SmartDeviceServer is a device management software widely used in enterprise environments to manage and configure mobile devices and other endpoints. It helps IT administrators streamline operations and enforce security policies across connected devices. This software is commonly used in industries such as retail, logistics, and healthcare to maintain efficiency and compliance. Ivanti provides both on-premises and cloud-based deployment options for flexibility. With its centralized management capabilities, it reduces overhead and improves operational control.

This vulnerability, identified as CVE-2024-38653, arises from improper processing of XML input in the Ivanti Avalanche SmartDeviceServer. Specifically, it allows attackers to exploit XML External Entities (XXE) to access sensitive files on the affected system. An unauthenticated remote attacker can send specially crafted XML payloads to trigger this vulnerability. If successfully exploited, attackers can read arbitrary files, potentially exposing critical information.

The XXE vulnerability affects the endpoint /mdm/checkin in the Ivanti Avalanche SmartDeviceServer. Attackers can inject malicious XML payloads containing external entity declarations, which reference arbitrary files on the server. The Content-Type header must be set to application/xml to craft an exploit request. Upon processing the payload, the server attempts to resolve the external entities, exposing sensitive files or system configurations. This flaw results from improper validation of XML input, leaving the system vulnerable to unauthorized file access.

Possible Effects:

  • Unauthorized access to sensitive server files, potentially exposing credentials or configuration details.
  • Increased risk of further attacks, such as privilege escalation or lateral movement within the network.
  • Compromise of data integrity, confidentiality, and privacy on affected systems.
  • Reputation damage and compliance violations for organizations using the vulnerable software.

Security for Everyone provides a comprehensive Cyber Threat Exposure Management platform to safeguard your digital assets. With this scanner, you can detect critical vulnerabilities like XXE in your systems before attackers exploit them. By using our platform, you benefit from automated scans, detailed reporting, and actionable remediation steps. Join today to strengthen your cybersecurity posture and protect your organization's valuable data. Stay ahead of threats with our cutting-edge tools and expertise.

References:

Solution Advice
  • Update Software: Apply the latest patches or updates from Ivanti to address the vulnerability.
  • Input Validation: Implement strict validation for XML input, disallowing external entity declarations.
  • Disable DTD Parsing: Configure the XML parser to disable DTD processing entirely.
  • Use a Firewall: Restrict unauthorized access to the /mdm/checkin endpoint with firewall rules.
  • Monitor Logs: Regularly monitor logs for suspicious XML payloads and unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.