2.7
CVE-2025-5450
- EPSS 0.26%
- Veröffentlicht 08.07.2025 15:15:31
- Zuletzt bearbeitet 15.07.2025 13:23:45
- Erkennungen
Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin with read-only rights to modify settings that should be restricted.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Connect Secure Version < 22.7
Ivanti ≫ Connect Secure Version 22.7 Update -
Ivanti ≫ Connect Secure Version 22.7 Update r1
Ivanti ≫ Connect Secure Version 22.7 Update r1.1
Ivanti ≫ Connect Secure Version 22.7 Update r1.2
Ivanti ≫ Connect Secure Version 22.7 Update r1.3
Ivanti ≫ Connect Secure Version 22.7 Update r1.4
Ivanti ≫ Connect Secure Version 22.7 Update r1.5
Ivanti ≫ Connect Secure Version 22.7 Update r2
Ivanti ≫ Connect Secure Version 22.7 Update r2.1
Ivanti ≫ Connect Secure Version 22.7 Update r2.2
Ivanti ≫ Connect Secure Version 22.7 Update r2.3
Ivanti ≫ Connect Secure Version 22.7 Update r2.4
Ivanti ≫ Connect Secure Version 22.7 Update r2.5
Ivanti ≫ Connect Secure Version 22.7 Update r2.6
Ivanti ≫ Connect Secure Version 22.7 Update r2.7
Ivanti ≫ Policy Secure Version < 22.7
Ivanti ≫ Policy Secure Version 22.7 Update -
Ivanti ≫ Policy Secure Version 22.7 Update r1
Ivanti ≫ Policy Secure Version 22.7 Update r1.1
Ivanti ≫ Policy Secure Version 22.7 Update r1.2
Ivanti ≫ Policy Secure Version 22.7 Update r1.3
Ivanti ≫ Policy Secure Version 22.7 Update r1.4
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.179 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 2.7 | 1.2 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
|
| 3c1d8aa1-5a33-4ea4-8992-aadd6440af75 | 6.3 | 2.8 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
|
CWE-602 Client-Side Enforcement of Server-Side Security
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
https://forums.ivanti.com/s/article/July-Security-Advisory-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Multiple-CVEs