PT-2025-6242 · Ivanti · Ivanti Connect Secure
Published
2025-02-11
·
Updated
2026-05-04
·
CVE-2025-22467
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ivanti Connect Secure versions prior to 22.7R2.6
Description
A stack-based buffer overflow in Ivanti Connect Secure allows a remote authenticated attacker to achieve remote code execution. The issue is actively exploited. Approximately 3.2 million services are found to be vulnerable, with the top affected countries being the US and Japan. Around 2850 IP addresses are seen unpatched worldwide.
Recommendations
To resolve the issue, download and install Ivanti Connect Secure version 22.7R2.6 or later. As a temporary workaround, consider restricting access to the vulnerable component until a patch is applied.
Fix
RCE
Stack Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ivanti Connect Secure