CVE-2025-8310

Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take over admin accounts by resetting the password
Configurations

Configuration 1 (hide)

cpe:2.3:a:ivanti:virtual_application_delivery_controller:*:*:*:*:*:*:*:*

History

12 Jan 2026, 18:50

Type Values Removed Values Added
First Time Ivanti virtual Application Delivery Controller
Ivanti
CPE cpe:2.3:a:ivanti:virtual_application_delivery_controller:*:*:*:*:*:*:*:*
References () https://forums.ivanti.com/s/article/August-Security-Advisory-Ivanti-Virtual-Application-Delivery-Controller-vADC-previously-vTM-CVE-2025-8310?language=en_US - () https://forums.ivanti.com/s/article/August-Security-Advisory-Ivanti-Virtual-Application-Delivery-Controller-vADC-previously-vTM-CVE-2025-8310?language=en_US - Vendor Advisory

13 Aug 2025, 17:34

Type Values Removed Values Added
Summary
  • (es) La falta de autorización en la consola de administración de Ivanti Virtual Application Delivery Controller anterior a la versión 22.9 permite que un atacante autenticado remoto tome el control de las cuentas de administrador restableciendo la contraseña.

12 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-12 15:15

Updated : 2026-01-12 18:50


NVD link : CVE-2025-8310

Mitre link : CVE-2025-8310

CVE.ORG link : CVE-2025-8310


JSON object : View

Products Affected

ivanti

  • virtual_application_delivery_controller
CWE
CWE-862

Missing Authorization