2025年4月7日星期一

Ivanti Products Remote Code Execution Vulnerability

Ivanti Products Remote Code Execution Vulnerability

Release Date: 7 Apr 2025

RISK: Extremely High Risk

TYPE: Operating Systems - Networks OS

A vulnerability has been identified in Ivanti Products. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note:

CVE-2025-22457 is being exploited in the wild. A remote, unauthenticated attacker could exploit this vulnerability to trigger execute code on the target device.


Impact

  • Remote Code Execution

System / Technologies affected

Versions prior or equal to:

 

  • Pulse Connect Secure version 9.1R18.9 (end-of-support)
  • Ivanti Connect Secure version 22.7R2.5
  • Ivanti Policy Secure version 22.7R1.3
  • ZTA Gateways version 22.8R2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Apache Tomcat 阻斷服務漏洞

Apache Tomcat 阻斷服務漏洞 發佈日期: 2025年08月14日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache...