Ivanti Connect Secure vulnerabilities

130 known vulnerabilities affecting ivanti/connect_secure.

Total CVEs
130
CISA KEV
14
actively exploited
Public exploits
10
Exploited in wild
12
Severity breakdown
CRITICAL15HIGH67MEDIUM46LOW2

Vulnerabilities

Page 2 of 7
CVE-2025-0293LOWCVSS 2.7fixed in 22.7v22.72025-07-08
CVE-2025-0293 [LOW] CWE-93 CVE-2025-0293: CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before vers CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to write to a protected configuration file on disk.
nvd
CVE-2025-22457CRITICALCVSS 9.8KEVPoCfixed in 22.7v22.72025-04-03
CVE-2025-22457 [CRITICAL] CWE-121 CVE-2025-22457: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
nvd
CVE-2024-38657MEDIUMCVSS 4.9fixed in 22.7v22.7+1 more2025-02-21
CVE-2024-38657 [MEDIUM] CWE-73 CVE-2024-38657: External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy S External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.
cvelistv5nvd
CVE-2024-10644HIGHCVSS 7.2fixed in 22.7v22.72025-02-11
CVE-2024-10644 [HIGH] CWE-94 CVE-2024-10644: Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before vers Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
nvd
CVE-2025-22467HIGHCVSS 8.8≤ 22.7v22.72025-02-11
CVE-2025-22467 [HIGH] CWE-121 CVE-2025-22467: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authe A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.
nvd
CVE-2024-13842MEDIUMCVSS 4.4≤ 22.7v22.72025-02-11
CVE-2024-13842 [MEDIUM] CWE-321 CVE-2024-13842: A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before ver A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
nvd
CVE-2024-13830MEDIUMCVSS 6.1fixed in 22.7v22.72025-02-11
CVE-2024-13830 [MEDIUM] CWE-79 CVE-2024-13830: Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before versi Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
nvd
CVE-2024-13843MEDIUMCVSS 4.4≤ 22.7v22.72025-02-11
CVE-2024-13843 [MEDIUM] CWE-312 CVE-2024-13843: Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
nvd
CVE-2024-12058MEDIUMCVSS 4.9fixed in 22.7v22.72025-02-11
CVE-2024-12058 [MEDIUM] CWE-73 CVE-2024-12058: External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy S External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.
nvd
CVE-2025-0282CRITICALCVSS 9.0KEVPoCv22.7≥ 22.7R2, ≤ 22.7R2.42025-01-08
CVE-2025-0282 [CRITICAL] CWE-121 CVE-2025-0282: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
cvelistv5nvd
CVE-2025-0283HIGHCVSS 7.0fixed in 9.1≥ 22.2, < 22.7+5 more2025-01-08
CVE-2025-0283 [HIGH] CWE-121 CVE-2025-0283: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.
nvd
CVE-2024-37401HIGHCVSS 7.5fixed in 22.7v22.7+1 more2024-12-12
CVE-2024-37401 [HIGH] CWE-125 CVE-2024-37401: An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unau An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.
cvelistv5nvd
CVE-2024-37377HIGHCVSS 7.5fixed in 22.7v22.7+1 more2024-12-12
CVE-2024-37377 [HIGH] CWE-787 CVE-2024-37377: A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remo A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.
cvelistv5nvd
CVE-2024-9844HIGHCVSS 8.8fixed in 22.7v22.72024-12-10
CVE-2024-9844 [HIGH] CWE-602 CVE-2024-9844: Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before vers Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.
nvd
CVE-2024-11634HIGHCVSS 7.2fixed in 22.7v22.72024-12-10
CVE-2024-11634 [HIGH] CWE-77 CVE-2024-11634: Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before v Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)
nvd
CVE-2024-11633HIGHCVSS 7.2fixed in 22.7v22.72024-12-10
CVE-2024-11633 [HIGH] CWE-88 CVE-2024-11633: Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated at Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution
nvd
CVE-2024-38656CRITICALCVSS 9.1fixed in 22.7v22.7+2 more2024-11-13
CVE-2024-38656 [CRITICAL] CWE-88 CVE-2024-38656: Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy S Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
cvelistv5nvd
CVE-2024-39711CRITICALCVSS 9.1fixed in 22.7v22.7+2 more2024-11-13
CVE-2024-39711 [CRITICAL] CWE-88 CVE-2024-39711: Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy S Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
cvelistv5nvd
CVE-2024-39712CRITICALCVSS 9.1fixed in 22.7v22.7+2 more2024-11-13
CVE-2024-39712 [CRITICAL] CWE-88 CVE-2024-39712: Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy S Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
cvelistv5nvd
CVE-2024-39710CRITICALCVSS 9.1fixed in 22.7v22.7+2 more2024-11-13
CVE-2024-39710 [CRITICAL] CWE-88 CVE-2024-39710: Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy S Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
cvelistv5nvd