Description
Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to achieve remote code execution
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
6.4.8.8008
References
forums.ivanti.com/...-2025-8296-CVE-2025-8297?language=en_US