CVE-2025-22457β€”Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

PUBLISHEDvulnerability record
2025-04-04 Β· last modified June 21, 2025

Metadata

CVE ID:
CVE-2025-22457
Project:
Ivanti
Product:
Connect Secure, Policy Secure, and ZTA Gateways
Date Added:
2025-04-04
Due Date:
2025-04-11
Last Updated:
June 21, 2025

Vulnerability Name

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Description

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
KNOWN

Action

Apply mitigations as set forth in the CISA instructions linked below.

Additional Notes

Related News Articles

Related Weaknesses