Ivanti Policy Secure vulnerabilities
78 known vulnerabilities affecting ivanti/policy_secure.
Total CVEs
78
CISA KEV
8
actively exploited
Public exploits
8
Exploited in wild
6
Severity breakdown
CRITICAL8HIGH37MEDIUM31LOW2
Vulnerabilities
Page 2 of 4
CVE-2025-0293LOWCVSS 2.7fixed in 22.7v22.72025-07-08
CVE-2025-0293 [LOW] CWE-93 CVE-2025-0293: CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before vers
CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to write to a protected configuration file on disk.
nvd
CVE-2025-22457CRITICALCVSS 9.8KEVPoCfixed in 22.7v22.72025-04-03
CVE-2025-22457 [CRITICAL] CWE-121 CVE-2025-22457: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
nvd
CVE-2024-38657MEDIUMCVSS 4.9fixed in 22.7v22.7+1 more2025-02-21
CVE-2024-38657 [MEDIUM] CWE-73 CVE-2024-38657: External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy S
External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.
cvelistv5nvd
CVE-2024-10644HIGHCVSS 7.2fixed in 22.7v22.72025-02-11
CVE-2024-10644 [HIGH] CWE-94 CVE-2024-10644: Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before vers
Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
nvd
CVE-2024-13842MEDIUMCVSS 4.4≤ 22.7v22.72025-02-11
CVE-2024-13842 [MEDIUM] CWE-321 CVE-2024-13842: A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before ver
A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
nvd
CVE-2024-13830MEDIUMCVSS 6.1fixed in 22.7v22.72025-02-11
CVE-2024-13830 [MEDIUM] CWE-79 CVE-2024-13830: Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before versi
Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
nvd
CVE-2024-13843MEDIUMCVSS 4.4≤ 22.7v22.72025-02-11
CVE-2024-13843 [MEDIUM] CWE-312 CVE-2024-13843: Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy
Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
nvd
CVE-2024-12058MEDIUMCVSS 4.9fixed in 22.7v22.72025-02-11
CVE-2024-12058 [MEDIUM] CWE-73 CVE-2024-12058: External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy S
External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.
nvd
CVE-2025-0282CRITICALCVSS 9.0KEVPoCv22.7≥ 22.7R1, ≤ 22.7R1.22025-01-08
CVE-2025-0282 [CRITICAL] CWE-121 CVE-2025-0282: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
cvelistv5nvd
CVE-2025-0283HIGHCVSS 7.0fixed in 22.7v22.7+1 more2025-01-08
CVE-2025-0283 [HIGH] CWE-121 CVE-2025-0283: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.
cvelistv5nvd
CVE-2024-37401HIGHCVSS 7.5fixed in 22.7v22.72024-12-12
CVE-2024-37401 [HIGH] CWE-125 CVE-2024-37401: An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unau
An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.
nvd
CVE-2024-37377HIGHCVSS 7.5fixed in 22.7v22.72024-12-12
CVE-2024-37377 [HIGH] CWE-787 CVE-2024-37377: A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remo
A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.
nvd
CVE-2024-11634HIGHCVSS 7.2fixed in 22.7v22.72024-12-10
CVE-2024-11634 [HIGH] CWE-77 CVE-2024-11634: Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before v
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)
nvd
CVE-2024-38656CRITICALCVSS 9.1fixed in 22.7v22.7+1 more2024-11-13
CVE-2024-38656 [CRITICAL] CWE-88 CVE-2024-38656: Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy S
Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
cvelistv5nvd
CVE-2024-39711CRITICALCVSS 9.1fixed in 22.7v22.7+1 more2024-11-13
CVE-2024-39711 [CRITICAL] CWE-88 CVE-2024-39711: Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy S
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
cvelistv5nvd
CVE-2024-39712CRITICALCVSS 9.1fixed in 22.7v22.7+1 more2024-11-13
CVE-2024-39712 [CRITICAL] CWE-88 CVE-2024-39712: Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy S
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
cvelistv5nvd
CVE-2024-39710CRITICALCVSS 9.1fixed in 22.7v22.7+1 more2024-11-13
CVE-2024-39710 [CRITICAL] CWE-88 CVE-2024-39710: Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy S
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
cvelistv5nvd
CVE-2024-38655HIGHCVSS 7.2fixed in 22.7v22.7+2 more2024-11-13
CVE-2024-38655 [HIGH] CWE-88 CVE-2024-38655: Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy S
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
cvelistv5nvd
CVE-2024-39709HIGHCVSS 7.8fixed in 9.1≥ 22.1, < 22.7+3 more2024-11-13
CVE-2024-39709 [HIGH] CWE-732 CVE-2024-39709: Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx)
Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges.
cvelistv5nvd
CVE-2024-8495HIGHCVSS 7.5fixed in 22.7v22.72024-11-12
CVE-2024-8495 [HIGH] CWE-476 CVE-2024-8495: A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure
A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service.
nvd