CVE-2018-8902: Ivanti Avalanche

Medium severity, CVSS 6.5. EPSS: 1.7% chance of exploitation in the next 30 days.

An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to encrypt data. A user with access to system databases can use the discovered key to access potentially confidential stored data, which may include Wi-Fi passwords. This discovered key can be used for all instances of the product.

Affected products

  • Ivanti Avalanche: from 5.3, up to and including 6.2

Published 2018-06-29. Last modified 2026-06-17.