5.5
CVE-2025-5468
- EPSS 0.04%
- Veröffentlicht 12.08.2025 15:15:31
- Zuletzt bearbeitet 23.09.2025 18:17:23
- Quelle 3c1d8aa1-5a33-4ea4-8992-aadd64
- Teams Watchlist Login
- Unerledigt Login
Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files on disk.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Connect Secure Version < 22.7
Ivanti ≫ Connect Secure Version22.7 Update-
Ivanti ≫ Connect Secure Version22.7 Updater1
Ivanti ≫ Connect Secure Version22.7 Updater1.1
Ivanti ≫ Connect Secure Version22.7 Updater1.2
Ivanti ≫ Connect Secure Version22.7 Updater1.3
Ivanti ≫ Connect Secure Version22.7 Updater1.4
Ivanti ≫ Connect Secure Version22.7 Updater1.5
Ivanti ≫ Connect Secure Version22.7 Updater2
Ivanti ≫ Connect Secure Version22.7 Updater2.1
Ivanti ≫ Connect Secure Version22.7 Updater2.2
Ivanti ≫ Connect Secure Version22.7 Updater2.3
Ivanti ≫ Connect Secure Version22.7 Updater2.4
Ivanti ≫ Connect Secure Version22.7 Updater2.5
Ivanti ≫ Connect Secure Version22.7 Updater2.6
Ivanti ≫ Connect Secure Version22.7 Updater2.7
Ivanti ≫ Policy Secure Version < 22.7
Ivanti ≫ Policy Secure Version22.7 Update-
Ivanti ≫ Policy Secure Version22.7 Updater1
Ivanti ≫ Policy Secure Version22.7 Updater1.1
Ivanti ≫ Policy Secure Version22.7 Updater1.2
Ivanti ≫ Policy Secure Version22.7 Updater1.3
Ivanti ≫ Policy Secure Version22.7 Updater1.4
Ivanti ≫ Zero Trust Access Gateway Version22.8 Updater2.2
Ivanti ≫ Neurons For Secure Access Version < 22.8
Ivanti ≫ Neurons For Secure Access Version22.8 Updater1
Ivanti ≫ Neurons For Secure Access Version22.8 Updater1.1
Ivanti ≫ Neurons For Secure Access Version22.8 Updater1.2
Ivanti ≫ Neurons For Secure Access Version22.8 Updater1.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.097 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
3c1d8aa1-5a33-4ea4-8992-aadd6440af75 | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-61 UNIX Symbolic Link (Symlink) Following
The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.