CVE-2025-55141: High severity Ivanti Connect Secure vulnerability
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure authentication related settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55141?
CVE-2025-55141 is considered a high severity vulnerability due to missing authorization which can be exploited by authenticated attackers.
How do I fix CVE-2025-55141?
To fix CVE-2025-55141, upgrade to Ivanti Connect Secure 22.7R2.9, Ivanti Policy Secure 22.7R1.6, Ivanti ZTA Gateway 2.8R2.3-723, or Ivanti Neurons for Secure Access 22.8R1.4.
What products are affected by CVE-2025-55141?
CVE-2025-55141 affects Ivanti Connect Secure, Ivanti Policy Secure, Ivanti ZTA Gateway, and Ivanti Neurons for Secure Access.
What kind of attacks can CVE-2025-55141 enable?
CVE-2025-55141 may allow a remote authenticated attacker to gain unauthorized access to sensitive information and perform actions with read-only admin privileges.
When was the fix for CVE-2025-55141 deployed?
The fix for CVE-2025-55141 was deployed on August 2, 2025.