PT-2025-6242 · Ivanti · Ivanti Connect Secure
Published
2025-02-11
·
Updated
2025-08-04
·
CVE-2025-22467
CVSS v3.1
9.9
9.9
Critical
Base vector | Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
Ivanti Connect Secure versions prior to 22.7R2.6
**Description:**
A stack-based buffer overflow exists in Ivanti Connect Secure. This vulnerability allows a remote authenticated attacker to achieve remote code execution. Approximately 2850 unpatched instances have been observed worldwide, with the United States and Japan being the most affected countries, accounting for 852 and 384 instances respectively. The vulnerability is actively exploited.
**Recommendations:**
Ivanti Connect Secure versions prior to 22.7R2.6: Upgrade to version 22.7R2.6 or later.
Fix
RCE
Out of bounds Read
Stack Overflow
Related Identifiers
BDU:2025-01566
CVE-2025-22467
Affected Products
Ivanti Connect Secure
References · 42
- https://bdu.fstec.ru/vul/2025-01566 · Security Note
- https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-22467 · Security Note
- https://twitter.com/catnap707/status/1889502710464127009 · Twitter Post
- https://twitter.com/fofabot/status/1889857230117429539 · Twitter Post
- https://twitter.com/HunterMapping/status/1890219110044143736 · Twitter Post
- https://t.me/cvenotify/111881 · Telegram Post
- https://twitter.com/JohnGerhar76023/status/1890830591639069039 · Twitter Post
- https://t.me/thehackernews/6324 · Telegram Post
- https://twitter.com/TweetThreatNews/status/1890782741622370491 · Twitter Post
- https://twitter.com/socradar/status/1890024447857287494 · Twitter Post
- https://reddit.com/r/Action1/comments/1j8w79r/patch_tuesday_alert_march_2025 · Reddit Post
- https://twitter.com/CVEnew/status/1889341258730201391 · Twitter Post
- https://twitter.com/transilienceai/status/1892191624907665597 · Twitter Post
- https://twitter.com/transilienceai/status/1891648141545423315 · Twitter Post