CVE-2025-8712
- EPSS 0.46%
- Veröffentlicht 09.09.2025 15:12:38
- Zuletzt bearbeitet 24.09.2025 19:56:42
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote ...
CVE-2025-5468
- EPSS 0.06%
- Veröffentlicht 12.08.2025 15:15:31
- Zuletzt bearbeitet 23.09.2025 18:17:23
Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-...
CVE-2025-5466
- EPSS 0.74%
- Veröffentlicht 12.08.2025 15:15:31
- Zuletzt bearbeitet 23.09.2025 18:18:59
XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated atta...
CVE-2025-5462
- EPSS 0.43%
- Veröffentlicht 12.08.2025 14:56:19
- Zuletzt bearbeitet 23.09.2025 18:21:21
A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a ...
CVE-2025-5456
- EPSS 0.47%
- Veröffentlicht 12.08.2025 14:50:46
- Zuletzt bearbeitet 23.09.2025 18:24:58
A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows...
CVE-2025-22457
- EPSS 73.53%
- Veröffentlicht 03.04.2025 16:15:35
- Zuletzt bearbeitet 24.10.2025 14:29:56
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
CVE-2024-22024
- EPSS 94.25%
- Veröffentlicht 13.02.2024 04:15:07
- Zuletzt bearbeitet 31.10.2025 16:35:28
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.