CVE-2025-22457: Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
Other sources
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.
— CISA
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-22457?
CVE-2025-22457 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2025-22457?
To fix CVE-2025-22457, upgrade Ivanti Connect Secure to version 22.7R2.6, Ivanti Policy Secure to version 22.7R1.4, or Ivanti ZTA Gateways to version 22.8R2.2.
Who is affected by CVE-2025-22457?
CVE-2025-22457 affects users of Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti ZTA Gateways prior to their respective patched versions.
What type of vulnerability is CVE-2025-22457?
CVE-2025-22457 is classified as a stack-based buffer overflow vulnerability.
Can CVE-2025-22457 be exploited remotely?
Yes, CVE-2025-22457 can be exploited by a remote unauthenticated attacker.