Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2025-22457

 

Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2025-22457

Published: April 3, 2025 / Updated: July 22, 2025


Vulnerability identifier: #VU106969
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22457
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when handling network requests. A remote unauthenticated attacker can send specially crafted packets to the device, trigger a stack-based buffer overflow and execute arbitrary code on the target system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Neurons for ZTA gateways

How to mitigate CVE-2025-22457

Install updates from vendor's website.

Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 22.7R2.6
Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 22.7R1.5
Ivanti Neurons for ZTA gateways - update to 22.8R2.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins