Ivanti has released security updates for Ivanti Connect Secure (ICS), Ivanti Policy Secure (IPS), and Ivanti Secure Access Client (ISAC) to address multiple vulnerabilities, including three critical severity problems. The company learned about the flaws through its responsible disclosure program from security researchers at CISA and Akamai, and through the HackerOne bug bounty platform. Ivanti notes in the security bulletin that it received no reports about any of the issues being actively exploited in the wild. However, it it recommends that users install the security updates as soon as possible. The three critical security vulnerabilities Ivanti patched are the following: Exploiting any of the three issues is possible from a remote location but an attacker needs to be authenticated. Furthermore, for two of them admin privileges are necessary to achieve remote code execution or to write arbitrary files. Despite this, the risk is still considerable as insider threats or attackers who have stolen credentials via phishing, previous breaches, or via brute forcing passwords, can still leverage the flaws for malicious operations. There are also five more flaws included in the bulletin, ranging from medium to high severity. Issues include cross-site scripting (XSS) issues, hardcoded keys, cleartext storage of sensitive data, and insufficient permissions. The vulnerabilities impact ICS 22.7R2.5 and older, IPS 22.7R1.2 and older, and ISAC 22.7R4 and below. Details about which produc...
Ivanti fixes three critical flaws in Connect Secure & Policy Secure
BleepingComputer
·Bill Toulas
·Published Feb 12, 2025
·Updated
Affected Software
7 affected components
Ivanti Connect Secure=22.7R2.5
Ivanti Policy Secure=22.7R1.2
Ivanti Secure Access Client=22.7R4
Ivanti Pulse Connect Secure=9.x
Ivanti Connect Secure
Ivanti Policy Secure
Ivanti Secure Access Client
Frequently Asked Questions
1
What vulnerabilities were fixed in the Ivanti security updates?
The updates addressed three critical severity vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure.
2
Which Ivanti products are affected by the recent security updates?
The affected products include Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Secure Access Client.
3
What versions of Ivanti products require immediate updates according to the article?
Users are advised to update to Ivanti Connect Secure version 22.7R2.5, Policy Secure version 22.7R1.2, and Secure Access Client version 22.7R4.
4
Why is it important to update Ivanti products promptly?
Prompt updates are crucial to protect against exploitations of the critical vulnerabilities outlined.
5
Did the article specify whether any incidents related to these vulnerabilities have occurred?
The article does not mention any specific incidents associated with these vulnerabilities.