
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-8297 is an incomplete restriction of configuration vulnerability in Ivanti Avalanche that allows a remote authenticated attacker with administrative privileges to achieve remote code execution (RCE). It affects Ivanti Avalanche (on-premise) versions prior to 6.4.8.8008 and is classified under CWE-434 (Unrestricted Upload of File with Dangerous Type). The vulnerability was published on August 12, 2025, with a patch released on August 15, 2025. It carries a CVSS v3.1 base score of 7.2 (High) (Ivanti Advisory, Red Hat CVE).
The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type), stemming from incomplete restriction of configuration options within Ivanti Avalanche. An authenticated attacker with admin-level privileges can abuse misconfigured or insufficiently restricted configuration interfaces to upload or deploy files of dangerous types, ultimately achieving remote code execution on the server. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require high privileges (admin credentials). Zero Day Initiative published advisories ZDI-25-856 and ZDI-25-857 related to this vulnerability (ZDI Advisory 857, ZDI Advisory 856).
Successful exploitation allows a remote admin-level attacker to execute arbitrary code on the affected Ivanti Avalanche system, resulting in high confidentiality, integrity, and availability impact. This could lead to complete system compromise, enabling unauthorized data access and exfiltration, system manipulation, and potential lateral movement within the enterprise network. Given Avalanche's role as a mobile device management (MDM) platform, compromise could extend to managed endpoints and sensitive device configurations (Red Hat CVE, Ivanti Advisory).
Ivanti has released a patch in Avalanche version 6.4.8.8008, which addresses CVE-2025-8297 along with the related CVE-2025-8296. Organizations should immediately upgrade to version 6.4.8.8008 or later. As additional hardening measures, administrators should enforce multi-factor authentication (MFA) for all admin accounts, implement strict access controls and least-privilege principles, audit admin account activity, and limit network exposure of the Avalanche management interface (Ivanti Advisory).
The vulnerability received early attention on Mastodon's infosec.exchange community shortly after disclosure on August 12, 2025. Zero Day Initiative published two related advisories (ZDI-25-856 and ZDI-25-857) on August 19, 2025, providing additional technical context. Qualys included detection coverage in its August 2025 web application detections roundup, and ENISA registered the vulnerability as EUVD-2025-24258 (ZDI Advisory 857, Qualys Notifications).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."