EUVD-2025-1580
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 8 Jan 2025. Evidence sources: cisa_kev.
- ENISA score
- 9.0 · CVSS 3.1
- Advisory evidence
- 2 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2025-0005Kwetsbaarheden verholpen in Ivanti Connect Secure en Policy Secure
