• News/
  • https://www.bleepingcomputer.com/news/security/ivanti-fixes-three-critical-flaws-in-connect-secure-and-policy-secure/

Ivanti fixes three critical flaws in Connect Secure & Policy Secure

BleepingComputer
·
Bill Toulas
·
Published Feb 12, 2025
·
Updated

Ivanti has released security updates for Ivanti Connect Secure (ICS), Ivanti Policy Secure (IPS), and Ivanti Secure Access Client (ISAC) to address multiple vulnerabilities, including three critical severity problems. The company learned about the flaws through its responsible disclosure program from security researchers at CISA and Akamai, and through the HackerOne bug bounty platform. Ivanti notes in the security bulletin that it received no reports about any of the issues being actively exploited in the wild. However, it it recommends that users install the security updates as soon as possible. The three critical security vulnerabilities Ivanti patched are the following: Exploiting any of the three issues is possible from a remote location but an attacker needs to be authenticated. Furthermore, for two of them admin privileges are necessary to achieve remote code execution or to write arbitrary files. Despite this, the risk is still considerable as insider threats or attackers who have stolen credentials via phishing, previous breaches, or via brute forcing passwords, can still leverage the flaws for malicious operations. There are also five more flaws included in the bulletin, ranging from medium to high severity. Issues include cross-site scripting (XSS) issues, hardcoded keys, cleartext storage of sensitive data, and insufficient permissions. The vulnerabilities impact ICS 22.7R2.5 and older, IPS 22.7R1.2 and older, and ISAC 22.7R4 and below. Details about which produc...

Read full article

Affected Software

7 affected components
Ivanti Connect Secure=22.7R2.5
Ivanti Policy Secure=22.7R1.2
Ivanti Secure Access Client=22.7R4
Ivanti Pulse Connect Secure=9.x
Ivanti Connect Secure
Ivanti Policy Secure
Ivanti Secure Access Client
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities were fixed in the Ivanti security updates?

The updates addressed three critical severity vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure.

2

Which Ivanti products are affected by the recent security updates?

The affected products include Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Secure Access Client.

3

What versions of Ivanti products require immediate updates according to the article?

Users are advised to update to Ivanti Connect Secure version 22.7R2.5, Policy Secure version 22.7R1.2, and Secure Access Client version 22.7R4.

4

Why is it important to update Ivanti products promptly?

Prompt updates are crucial to protect against exploitations of the critical vulnerabilities outlined.

5

Did the article specify whether any incidents related to these vulnerabilities have occurred?

The article does not mention any specific incidents associated with these vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203