CVE-2025-5468 — UNIX Symbolic Link (Symlink) Following in Ivanti Connect Secure
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 76.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Description
Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files on disk.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6