Loading HuntDB...

CVE-2025-22457

CRITICAL
Published 2025-04-03T15:20:23.628Z
Actions:

CVSS Score

V3.1
9.0
/10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score Metrics
Exploitability: N/A Impact: N/A

Attack Vector Metrics

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED

Impact Metrics

Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

Available Exploits

No exploits available for this CVE.

Related News

GreenboneOS: Attackers Advance on Two New Ivanti EPMM Flaws

Just last month, CVE-2025-22457 (CVSS 9.8) affecting Ivanti Connect Secure, Policy Secure, and ZTA Gateways was recognized as a vector for ransomware. Now, two new CVEs have been added to the growing list of high-risk Ivanti vulnerabilities; CVE-2025-4427 and…

Greenbone.net 2025-05-28 09:57
菴処

Ivanti Connect Secure⒢識эCVE-2025-22457鐚≪絵儀 (2025.04.04) f絵儀違紊у申荐 遵с茴㍂榊∈茯 Ivanti ZTA Gateways patch Ivanti Policy Secure patch 散2025.05.15 篋 翫сс若 (ICT) 茵パ㍾鴻箴腆肴 筝h箴球㍂綽純 PulseSecureァッ腟 (紊у, 2025.04.18) 紊ICT㍾承絎潟翫札筝絲…

Ryukoku.ac.jp 2025-04-29 15:00
Ivanti Zero-Day CVE-2025-22457 Exploit Details Released

Researchers at Rapid7 published technical details and proof-of-concept exploit code for a critical zero-day vulnerability in Ivanti Connect The post Ivanti Zero-Day CVE-2025-22457 Exploit Details Released appeared first on Daily CyberSecurity.

SecurityOnline.info 2025-04-11 03:28
Ivanti Products Remote Code Execution Vulnerability

A vulnerability has been identified in Ivanti Products. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system. Note: CVE-2025-22457 is being exploited in the wild. A remote, unauthenticated attacker co…

Hkcert.org 2025-04-07 02:10
CISA Adds One Vulnerability to the KEV Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2025-22457 Ivanti Connect Secure, Policy Secure and ZTA Gateways Stack-Based Buffer Overflow Vulnerability T…

Cisa.gov 2025-04-04 12:00

Affected Products

Known Exploited Vulnerability

This vulnerability is actively being exploited in the wild

View KEV Details

Remediation Status

Overdue

Due Date

April 11, 2025

Added to KEV

April 4, 2025

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected Product

Vendor/Project: Ivanti
Product: Connect Secure, Policy Secure and ZTA Gateways

Ransomware Risk

Known Ransomware Use
KEV Catalog Version: 2025.04.04 Released: April 4, 2025

References

Published: 2025-04-03T15:20:23.628Z
Last Modified: 2025-04-24T03:55:16.988Z
Copied to clipboard!