Ivanti Connect Secure Sensitive Information Log Injection Vulnerability

Vulnerability

A vulnerability exists in Ivanti Connect Secure (ICS) versions prior to 22.7R2.8) that allows local authenticated attackers to insert sensitive information into a log file, which can then be accessed to obtain that information.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information through log files.

Remediation

Users can upgrade to Ivanti Connect Secure version 22.7R2.8 to address this vulnerability. The update is available through the Ivanti Download Portal.

Added: Jul 8, 2025, 5:06 PM
Updated: Jul 8, 2025, 5:06 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
4.0
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.