Server-Side Request Forgery (SSRF) in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2025-0292

 

Server-Side Request Forgery (SSRF) in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2025-0292

Published: July 8, 2025


Vulnerability identifier: #VU112541
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-0292
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote user to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input. A remote privileged user can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)

How to mitigate CVE-2025-0292

Install updates from vendor's website.

Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 22.7R1.5
Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 22.7R2.8

External References

Related Security Bulletins