Ivanti Connect Secure and Policy Secure Reflected Cross-Site Scripting Vulnerability Allowing Admin Privileges

Vulnerability

A reflected cross-site scripting vulnerability has been identified in Ivanti Connect Secure (ICS) versions prior to 22.7R2.6 and Ivanti Policy Secure (IPS) versions prior to 22.7R1.3. This vulnerability allows a remote, unauthenticated attacker to gain administrative privileges, although it requires user interaction to exploit.

Impact

Exploitation of this vulnerability allows a remote, unauthenticated attacker to obtain administrative privileges on the affected system.

Remediation

Users can upgrade to Ivanti Connect Secure version 22.7R2.6 or Ivanti Policy Secure version 22.7R1.3. These versions are available through the Ivanti Download Portal.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
5.0
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.