[CIVN-2025-0210] Multiple Vulnerabilities in Ivanti Products

By Published On: September 12, 2025

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Ivanti Products 
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Ivanti Connect Secure versions prior to 22.7R2.8
Ivanti Policy Secure versions prior to 22.7R1.5
Ivanti ZTA Gateways versions prior to 22.8R2.2
Ivanti Neurons for Secure Access versions prior to 22.8R1.3
Overview
Multiple vulnerabilities have been reported in Ivanti products, which could be exploited by a remote attacker to bypass security restrictions, gain elevated privileges, cause a denial of service condition or perform Server-Side Request Forgery (SSRF) & Cross-Site Request Forgery (CSRF) attacks on the targeted system.
Target Audience:
Individuals and end-user organisations using Ivanti products.
Risk Assessment:
High risk of unauthorised access and system instability.
Impact Assessment:
Potential for data theft and system compromise.
Description
Ivanti Connect Secure and Ivanti Policy Secure provide secure access and network access control solutions.
These vulnerabilities exist in Ivanti products due to improper validation of user-supplied input, reflected text injection, missing authorisation checks, and unchecked return value errors.
Successful exploitation of these vulnerabilities could allow a remote attacker to bypass security restrictions, gain elevated privileges, cause a denial of service condition or perform Server-Side Request Forgery (SSRF) & Cross-Site Request Forgery (CSRF) attacks on the targeted system.
Solution
Apply appropriate updates as released by Ivanti to affected products:
https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs?language=en_US
Vendor Information
Ivanti
https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs?language=en_US
References
Ivanti
https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs?language=en_US
CVE Name
CVE-2025-55139
CVE-2025-55141
CVE-2025-55142
CVE-2025-55143
CVE-2025-55144
CVE-2025-55145
CVE-2025-55146
CVE-2025-55147
CVE-2025-55148
CVE-2025-8711
CVE-2025-8712
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmjEFOoACgkQ3jCgcSdc
ys9JtA//QAyPQvpfW/HcleWgAg3V9Nzwl44LWCoD5xd0V9WSFdwx2Uq25Fazns4C
yXUhR/14rnWXlgoXJLTQd/YzVx2Bgoc+K9Rfunx8eJW59HMdHa+bcHdJS7mb0noI
qUdTRS4tqvb2s3cqZJBc7SThTU8TP5ToCnHH6G92EwrNQPHxix2WIInvhBXPR8KA
mUsZHx/DzrUlShmOjJTpEw6MBWL5hwX7IjqjmorcmpfEN1aR4+eUfDQgYj9PsrTH
Xk/fyZoFZ3+zdIMqnJ6hij0cFayEI4fiKdujz1xPNB4AEsqYmSjfYN1ztYFt4Quy
/TLThsCDQJnTPmb3wVRd6SjjImFA/nrg4dpNlMDNOqHhFkCwkpNNw9Fdrpz4grlE
big0lPSVBaNFE1JiQd7dyfBmmOMtPqxCZjyCIq6+I3PqENKoeuabzqC+p/YDei5x
GS9QlyBZawZKHX+ln3dnEEBl02LnrohOvgdZLJZS4cjKTLZumiDEsyip+WLIV1yr
tNqPVZM1Tja3DDXom13QqaGKa+3zb4ALZr0EyHHwU1y/UYN/7IaQzt+H4FmX9Mnt
jKOelh27o6QEPnSx5RJ6BMHWgDx+JM0H+3/lW9k2iRLdSjHWYevroHf+SqgTeY3p
JP2plgnuve/VXSH9WlSiPsKZlqcwF5XhWVMdQkGPQrYmvmJKAq8=
=Ja6I
—–END PGP SIGNATURE—–

Share this article