CVE-2025-55139Server-Side Request Forgery in Ivanti Connect Secure

Severity
6.8MEDIUMNVD
EPSS
0.6%
top 31.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9

Description

SSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to enumerate internal services.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:NExploitability: 2.3 | Impact: 4.0

Affected Packages4 packages

🔴Vulnerability Details

2
CVEList
CVE-2025-55139: SSRF in Ivanti Connect Secure before 222025-09-09
GHSA
GHSA-gg29-529g-r9m2: SSRF in Ivanti Connect Secure before 222025-09-09
CVE-2025-55139 — Server-Side Request Forgery in Ivanti | cvebase