7.5
CVE-2025-5462
- EPSS 1.08%
- Veröffentlicht 12.08.2025 14:56:19
- Zuletzt bearbeitet 23.09.2025 18:21:21
- Erkennungen
A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Connect Secure Version < 22.7
Ivanti ≫ Connect Secure Version 22.7 Update -
Ivanti ≫ Connect Secure Version 22.7 Update r1
Ivanti ≫ Connect Secure Version 22.7 Update r1.1
Ivanti ≫ Connect Secure Version 22.7 Update r1.2
Ivanti ≫ Connect Secure Version 22.7 Update r1.3
Ivanti ≫ Connect Secure Version 22.7 Update r1.4
Ivanti ≫ Connect Secure Version 22.7 Update r1.5
Ivanti ≫ Connect Secure Version 22.7 Update r2
Ivanti ≫ Connect Secure Version 22.7 Update r2.1
Ivanti ≫ Connect Secure Version 22.7 Update r2.2
Ivanti ≫ Connect Secure Version 22.7 Update r2.3
Ivanti ≫ Connect Secure Version 22.7 Update r2.4
Ivanti ≫ Connect Secure Version 22.7 Update r2.5
Ivanti ≫ Connect Secure Version 22.7 Update r2.6
Ivanti ≫ Connect Secure Version 22.7 Update r2.7
Ivanti ≫ Policy Secure Version < 22.7
Ivanti ≫ Policy Secure Version 22.7 Update -
Ivanti ≫ Policy Secure Version 22.7 Update r1
Ivanti ≫ Policy Secure Version 22.7 Update r1.1
Ivanti ≫ Policy Secure Version 22.7 Update r1.2
Ivanti ≫ Policy Secure Version 22.7 Update r1.3
Ivanti ≫ Policy Secure Version 22.7 Update r1.4
Ivanti ≫ Zero Trust Access Gateway Version 22.8 Update r2.2
Ivanti ≫ Neurons For Secure Access Version < 22.8
Ivanti ≫ Neurons For Secure Access Version 22.8 Update r1
Ivanti ≫ Neurons For Secure Access Version 22.8 Update r1.1
Ivanti ≫ Neurons For Secure Access Version 22.8 Update r1.2
Ivanti ≫ Neurons For Secure Access Version 22.8 Update r1.3
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.08% | 0.613 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 3c1d8aa1-5a33-4ea4-8992-aadd6440af75 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-122 Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
https://forums.ivanti.com/s/article/August-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-Multiple-CVEs?language=en_US