Ivanti Products Multiple Vulnerabilities
Release Date: 10 Sep 2025
RISK: Medium Risk
TYPE: Operating Systems - Networks OS
Multiple vulnerabilities have been identified in Ivanti Products. A remote attacker could exploit these vulnerabilities to trigger cross-site scripting, security restriction bypass, denial of service condition and sensitive information disclosure on the targeted system.
Impact
- Denial of Service
- Security Restriction Bypass
- Information Disclosure
- Cross-Site Scripting
System / Technologies affected
- Ivanti Connect Secure (ICS) version 22.7R2.9 or 22.8R2 and prior
- Ivanti Policy Secure (IPS) version 22.7R1.6 and prior
- Ivanti ZTA Gateway version 22.8R2.3-723
- Ivanti Neurons for Secure Access version 22.8R1.4 and prior
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
- CVE-2025-8711
- CVE-2025-8712
- CVE-2025-55139
- CVE-2025-55141
- CVE-2025-55142
- CVE-2025-55143
- CVE-2025-55144
- CVE-2025-55145
- CVE-2025-55146
- CVE-2025-55147
- CVE-2025-55148
沒有留言:
發佈留言