CVE-2022-36974 is a critical remote code execution vulnerability affecting Ivanti Avalanche 6.3.2.3490, stemming from improper validation of user-supplied data leading to untrusted deserialization in the Web File Server service. Rated 9.8 CRITICAL, this flaw allows unauthenticated remote attackers to execute arbitrary code with full privileges, bypassing the existing authentication mechanism. The potential impact includes complete compromise of confidentiality, integrity, and availability of the affected system. While not currently listed in CISA's KEV catalog and lacking public exploit code, its high EPSS score and "Active" Hot List status indicate a significant potential for future exploitation, with some community discussion already present.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.3.2.3490, < 6.3.4CPE matchmatch criteria | cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.