CVE-2025-8297: Malicious File Upload
Published Aug 12, 2025
·Updated
Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to achieve remote code execution
Affected Software
2 affected components
Ivanti Avalanche<6.4.8.8008
Ivanti Avalanche<6.4.8.8008
Event History
Aug 12, 2025
CVE Published
via MITRE·02:37 PM
Data Sourced
via MITRE·02:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Dec 1, 57594
Event
via FIRST·05:37 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-8297?
CVE-2025-8297 has been rated as critical due to its potential for remote code execution.
2
How do I fix CVE-2025-8297?
To mitigate CVE-2025-8297, upgrade Ivanti Avalanche to version 6.4.8.8009 or later.
3
Who is affected by CVE-2025-8297?
CVE-2025-8297 affects all versions of Ivanti Avalanche prior to 6.4.8.8008.
4
What kind of attack does CVE-2025-8297 allow?
CVE-2025-8297 allows remote authenticated attackers with admin privileges to execute arbitrary code.
5
Is there a patch available for CVE-2025-8297?
Yes, a patch is available by updating Ivanti Avalanche to version 6.4.8.8009 or higher.