CRITICAL

CVE-2025-22457

Ivanti Connect Secure 2025-04-03 CVSS v3.1
CVSS
9.8
KEV

Description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

Summary dbcve.org

A stack-based buffer overflow in the web component of Ivanti Connect Secure, Policy Secure, and ZTA Gateways allows remote unauthenticated attackers to overflow a stack buffer and achieve remote code execution.

Mitigation

Upgrade Ivanti Connect Secure to version 22.7R2.6 or later, Policy Secure to 22.7R1.4 or later, or ZTA Gateways to 22.8R2.2 or later.

Weakness (CWE)

CWE-121 Stack-based Buffer Overflow
CWE-787 Out-of-bounds Write

EPSS Score

99.98%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE