← Back

Connect Secure

connect_secure

Vendor: Ivanti • 130 CVEs

CVEs (130)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ivanti
2Connect Secure
Policy Secure
Jul 15, 2025
Jul 8, 2025
N/A· v4
2.7 LOW· v3
N/A· v2
Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin with read-only rights...Show more
Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin with read-only rights to modify settings that should be restricted.Show less
1Ivanti
3Connect Secure
Policy SecureZero Trust Access Gateway
Oct 24, 2025
Apr 3, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to ac...Show more
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.Show less
1Ivanti
2Connect Secure
Policy Secure
Jul 9, 2025
Feb 21, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.
1Ivanti
1Connect Secure
Feb 20, 2025
Feb 11, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.
1Ivanti
2Connect Secure
Policy Secure
Feb 20, 2025
Feb 11, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
1Ivanti
2Connect Secure
Policy Secure
Feb 20, 2025
Feb 11, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
1Ivanti
2Connect Secure
Policy Secure
Feb 13, 2025
Feb 11, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
1Ivanti
2Connect Secure
Policy Secure
Jul 16, 2025
Feb 11, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.
1Ivanti
2Connect Secure
Policy Secure
Jul 14, 2025
Feb 11, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
3Connect Secure
Neurons For Zero Trust AccessPolicy Secure
Jan 14, 2025
Jan 8, 2025
N/A· v4
7.0 HIGH· v3
N/A· v2
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attac...Show more
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.Show less
1Ivanti
3Connect Secure
Neurons For Zero Trust AccessPolicy Secure
Oct 24, 2025
Jan 8, 2025
N/A· v4
9.0 CRITICAL· v3
N/A· v2
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated at...Show more
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.Show less
1Ivanti
2Connect Secure
Policy Secure
Jul 2, 2025
Dec 12, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.
1Ivanti
2Connect Secure
Policy Secure
Jul 2, 2025
Dec 12, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.
1Ivanti
1Connect Secure
Jan 17, 2025
Dec 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.
1Ivanti
2Connect Secure
Policy Secure
Jan 17, 2025
Dec 10, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not appl...Show more
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)Show less
1Ivanti
1Connect Secure
Jan 17, 2025
Dec 10, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution
1Ivanti
2Connect Secure
Policy Secure
Jul 11, 2025
Nov 13, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execut...Show more
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.Show less
1Ivanti
2Connect Secure
Policy Secure
Jul 11, 2025
Nov 13, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execu...Show more
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.Show less
1Ivanti
2Connect Secure
Policy Secure
Jul 11, 2025
Nov 13, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execut...Show more
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.Show less
1Ivanti
2Connect Secure
Policy Secure
Jul 16, 2025
Nov 13, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalat...Show more
Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges.Show less