Unrated severityCISA KEVNVD Advisory· Published Apr 3, 2025· Updated Feb 26, 2026
CVE-2025-22457
CVE-2025-22457
Description
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
Affected products
3- Ivanti/Connect Securev5Range: 22.7R2.6
- Ivanti/Neurons for ZTA gatewaysv5Range: 22.8R2.2
- Ivanti/Policy Securev5Range: 22.7R1.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.