Ivanti Connect Secure and Policy Secure Arbitrary File Read Vulnerability

Vulnerability

A vulnerability allowing external control of file names has been identified in Ivanti Connect Secure versions prior to 22.7R2.6 and Ivanti Policy Secure versions prior to 22.7R1.3. This vulnerability allows remote authenticated attackers with admin privileges to read arbitrary files.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files, potentially allowing for further exploitation or information disclosure.

Remediation

Users can upgrade to Ivanti Connect Secure version 22.7R2.6 or Ivanti Policy Secure version 22.7R1.3. These versions are available on the Ivanti Download Portal.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
2.5
exploitability
2.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.