6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Description
Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take over admin accounts by resetting the password
Basic Information
ID
CVE-2025-8310
Source
ivanti
Published
Aug 12, 2025 at 14:42
Modified
Aug 13, 2025 at 15:03
Affected Product
Vendor
Ivanti
Product
Virtual Application Delivery ControllerCWE-862
Version
22.9