VYPR
Unrated severityCISA KEVNVD Advisory· Published Apr 3, 2025· Updated Feb 26, 2026

CVE-2025-22457

CVE-2025-22457

Description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

Affected products

3
  • Ivanti/Connect Securev5
    Range: 22.7R2.6
  • Ivanti/Neurons for ZTA gatewaysv5
    Range: 22.8R2.2
  • Ivanti/Policy Securev5
    Range: 22.7R1.4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.