Fiche vulnérabilité
CVE-2021-42125 : faille élevée ivanti avalanche (CVSS 8.8)
Description
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 7 déc. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- ivanti avalanche