Ivanti Connect Secure
cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*
- >= 22.7R2, <= 22.7R2.4
- >= 9.1R18.9, <= 9.1R18.9
A stack-based buffer overflow vulnerability has been identified in Ivanti Connect Secure versions prior to 22.7R2.5, Ivanti Policy Secure versions prior to 22.7R1.2, and Ivanti Neurons for ZTA gateways versions prior to 22.7R2.3. This vulnerability allows a local authenticated attacker to escalate privileges.
Exploitation of this vulnerability could lead to unauthorized privilege escalation.
Users of Ivanti Connect Secure should upgrade to version 22.7R2.5. For Ivanti Policy Secure, the fix will be available in version 22.7R1.3, scheduled for release on January 21, 2025. Ivanti Neurons for ZTA Gateways have already been updated to the patched version 22.8R2.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.