CVE-2022-36982
published 2023-03-29CVE-2022-36982: This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication is required…
PriorityP270high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
73.76%
99.4th percentile
This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AgentTaskHandler class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose stored session cookies, leading to further compromise. Was ZDI-CAN-15967.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ivanti | avalanche | — | — |
| ivanti | avalanche | >= 6.3.3.101 < 6.3.4 | 6.3.4 |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit targets the AgentTaskHandler class in Ivanti Avalanche 6.3.3.101; monitor for path traversal patterns in requests routed to AgentTaskHandler endpoints ↗
- →Authentication bypass precedes file read exploitation; detect anomalous authenticated requests to AgentTaskHandler from unauthenticated or low-privilege sessions ↗
- →Post-exploitation objective is session cookie theft; monitor for unauthorized access or exfiltration of stored session cookie files on Ivanti Avalanche servers ↗
- ·Vulnerability is confirmed on Ivanti Avalanche version 6.3.3.101 specifically; scope of affected versions beyond this should be verified against vendor advisory ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vrvf-x4g2-cx9g: This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6
ghsa_unreviewed·2023-03-29
CVE-2022-36982 [HIGH] CWE-22 GHSA-vrvf-x4g2-cx9g: This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6
This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AgentTaskHandler class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose stored session cookies, leading to further compromise. Was ZDI-CAN-15967.
Ivanti
Ivanti Security Advisory: CVE-2022-36982
vendor_ivanti·2023-03-29·CVSS 7.5
CVE-2022-36982 [HIGH] CWE-22 Ivanti Security Advisory: CVE-2022-36982
Ivanti Security Advisory: CVE-2022-36982
This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AgentTaskHandler class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose stored session cookies, leading to further compromise. Was ZDI-CAN-15967.
CVE IDs: CVE-2022-36982
CVSS Base Score: 7.5
Severity: HIGH
CWEs: CWE-22
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-29
Published