CVE-2025-8297

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
12/08/2025
Last modified:
15/08/2025

Description

Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to achieve remote code execution

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ivanti:avalanche:*:*:*:*:premise:*:*:* 6.4.8.8008 (excluding)