CVE-2025-5468UNIX Symbolic Link (Symlink) Following in Ivanti Connect Secure

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 76.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files on disk.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

🔴Vulnerability Details

2
CVEList
CVE-2025-5468: Improper handling of symbolic links in Ivanti Connect Secure before version 222025-08-12
GHSA
GHSA-3pr6-5rrr-cqpq: Improper handling of symbolic links in Ivanti Connect Secure before version 222025-08-12
CVE-2025-5468 — UNIX Symbolic Link (Symlink) Following | cvebase