CVE-2025-55145: High severity Ivanti Connect Secure vulnerability
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker to hijack existing HTML5 connections.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55145?
CVE-2025-55145 is considered a high severity vulnerability due to the potential for remote authenticated attackers to hijack existing sessions.
How do I fix CVE-2025-55145?
To fix CVE-2025-55145, upgrade to Ivanti Connect Secure versions 22.7R2.9 or 22.8R2, Ivanti Policy Secure version 22.7R1.6, Ivanti ZTA Gateway version 2.8R2.3-723, or Ivanti Neurons for Secure Access version 22.8R1.4.
What versions of Ivanti products are affected by CVE-2025-55145?
CVE-2025-55145 affects Ivanti Connect Secure before 22.7R2.9 and 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723, and Ivanti Neurons for Secure Access before 22.8R1.4.
When was the fix for CVE-2025-55145 deployed?
The fix for CVE-2025-55145 was deployed on August 2, 2025.
What type of vulnerability is CVE-2025-55145?
CVE-2025-55145 is a missing authorization vulnerability that allows remote authenticated attackers to hijack HTML5 connections.