Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2025-22457
Published: April 3, 2025 / Updated: July 22, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when handling network requests. A remote unauthenticated attacker can send specially crafted packets to the device, trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Neurons for ZTA gateways
How to mitigate CVE-2025-22457
Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 22.7R1.5
Ivanti Neurons for ZTA gateways - update to 22.8R2.2