CVE Database · CVE-2025-22457
CVSS v3.1
9.0
EPSS
99.96%
Published
Apr 3, 2025
Modified
Oct 24, 2025
CISA Known Exploited Vulnerability
Added: 2025-04-04 · Due: 2025-04-11
Apply mitigations as set forth in the CISA instructions linked below.
Public PoC / Exploit (5)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses (CWE)
Affected Products (23)
References (2)