← Back

CVE-2025-22457

Published: Apr 3, 2025Modified: Oct 24, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

Affected (23)

3 products
Connect Secure
Policy Secure
Zero Trust Access Gateway
Configuration A
23 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Before 22.7
Version 22.7
Version 22.7 r1.1
Version 22.7 r1.2
Version 22.7 r1.3
Version 22.7 r1.4
Version 22.7 r1.5
Version 22.7 r1
Version 22.7 r2.1
Version 22.7 r2.2
Version 22.7 r2.3
Version 22.7 r2.4
Version 22.7 r2.5
Version 22.7 r2
Ivanti
Before 22.7
Version 22.7
Version 22.7 r1.1
Version 22.7 r1.2
Version 22.7 r1.3
Version 22.7 r1
Ivanti
Before 22.8
Version 22.8
Version 22.8 r2.1

References (2)

Timeline

No history available yet.