Link following in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2025-5468
Published: August 12, 2025
Vulnerability identifier: #VU113828
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-5468
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to read arbitrary files on the system.
The vulnerability exists due to an insecure link following issue. A local user can create a specially crafted symbolic link to a critical file on the system and read its contents.
Affected software
Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti Connect Secure (formerly Pulse Connect Secure)
How to mitigate CVE-2025-5468
Install updates from vendor's website.
Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 22.7R1.5
Ivanti Connect Secure (formerly Pulse Connect Secure) - addressed in versions 22.7R2.8, 22.8R2
Ivanti Connect Secure (formerly Pulse Connect Secure) - addressed in versions 22.7R2.8, 22.8R2