PT-2025-6242 · Ivanti · Ivanti Connect Secure

Published

2025-02-11

·

Updated

2025-08-04

·

CVE-2025-22467

CVSS v3.1
9.9
VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

Ivanti Connect Secure versions prior to 22.7R2.6

**Description:**

A stack-based buffer overflow exists in Ivanti Connect Secure. This vulnerability allows a remote authenticated attacker to achieve remote code execution. Approximately 2850 unpatched instances have been observed worldwide, with the United States and Japan being the most affected countries, accounting for 852 and 384 instances respectively. The vulnerability is actively exploited.

**Recommendations:**

Ivanti Connect Secure versions prior to 22.7R2.6: Upgrade to version 22.7R2.6 or later.

Fix

RCE

Out of bounds Read

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-01566
CVE-2025-22467

Affected Products

Ivanti Connect Secure