Ivanti
Ivanti Connect Secure: vulnerabilidades y CVE
Ivanti Connect Secure tiene 132 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 15 son críticas y 14 figuran en el catálogo de explotación activa de CISA.
CVE132
Últimos 12 meses0
Críticas15
Explotadas activamente14
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-22457 | Crítica (9.8) | 100% | ⚠ Explotación activa | 3 abr 2025 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to… |
| CVE-2025-0282 | Crítica (9) | 100% | ⚠ Explotación activa | 8 ene 2025 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated… |
| CVE-2024-21893 | Alta (8.2) | 100% | ⚠ Explotación activa | 31 ene 2024 | A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted… |
| CVE-2024-21887 | Crítica (9.1) | 100% | ⚠ Explotación activa | 12 ene 2024 | A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute… |
| CVE-2023-46805 | Alta (8.2) | 100% | ⚠ Explotación activa | 12 ene 2024 | An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks. |
| CVE-2020-8218 | Alta (7.2) | 32% | ⚠ Explotación activa | 30 jul 2020 | A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface. |
| CVE-2021-22899 | Alta (8.8) | 23% | ⚠ Explotación activa | 27 may 2021 | A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature |
| CVE-2021-22894 | Alta (8.8) | 41% | ⚠ Explotación activa | 27 may 2021 | A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room. |
| CVE-2021-22900 | Alta (7.2) | 14% | ⚠ Explotación activa | 27 may 2021 | A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the… |
| CVE-2019-11539 | Alta (7.2) | 99% | ⚠ Explotación activa | 26 abr 2019 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX… |
| CVE-2019-11510 | Crítica (10) | 100% | ⚠ Explotación activa | 8 may 2019 | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading… |
| CVE-2020-8243 | Alta (7.2) | 91% | ⚠ Explotación activa | 30 sept 2020 | A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution. |
| CVE-2020-8260 | Alta (7.2) | 96% | ⚠ Explotación activa | 28 oct 2020 | A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction. |
| CVE-2021-22893 | Crítica (10) | 47% | ⚠ Explotación activa | 23 abr 2021 | Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-8712 | Media (5.4) | 0.45% | — | 9 sept 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed… |
| CVE-2025-8711 | Media (5.4) | 0.33% | — | 9 sept 2025 | CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025)… |
| CVE-2025-55148 | Alta (7.6) | 0.56% | — | 9 sept 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on… |
| CVE-2025-55147 | Alta (8.8) | 0.61% | — | 9 sept 2025 | CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025)… |
| CVE-2025-55146 | Media (4.9) | 0.80% | — | 9 sept 2025 | An unchecked return value in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix… |
| CVE-2025-55145 | Alta (8.9) | 0.65% | — | 9 sept 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on… |
| CVE-2025-55144 | Media (5.4) | 0.56% | — | 9 sept 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on… |
| CVE-2025-55143 | Media (6.1) | 0.71% | — | 9 sept 2025 | Reflected text injection in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed… |
| CVE-2025-55142 | Alta (8.8) | 0.93% | — | 9 sept 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on… |
| CVE-2025-55141 | Alta (8.8) | 0.93% | — | 9 sept 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on… |
| CVE-2025-55139 | Media (6.8) | 0.91% | — | 9 sept 2025 | SSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025)… |
| CVE-2025-5468 | Media (5.5) | 0.36% | — | 12 ago 2025 | Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before… |
| CVE-2025-5466 | Media (4.9) | 0.68% | — | 12 ago 2025 | XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025)… |
| CVE-2025-5462 | Alta (7.5) | 1.1% | — | 12 ago 2025 | A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix… |
| CVE-2025-5456 | Alta (7.5) | 1.1% | — | 12 ago 2025 | A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix… |
| CVE-2025-5464 | Media (5.5) | 0.35% | — | 8 jul 2025 | Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker to obtain that information. |
| CVE-2025-0293 | Baja (2.7) | 0.46% | — | 8 jul 2025 | CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to write to a protected configuration file on… |
| CVE-2025-0292 | Media (4.9) | 0.64% | — | 8 jul 2025 | SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to access internal network services. |
| CVE-2025-5463 | Media (5.5) | 0.35% | — | 8 jul 2025 | Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local authenticated attacker to obtain that information. |
| CVE-2025-5451 | Media (4.9) | 0.79% | — | 8 jul 2025 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to trigger a denial of service. |
| CVE-2025-5450 | Baja (2.7) | 0.30% | — | 8 jul 2025 | Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin with read-only rights… |
| CVE-2025-22457 | Crítica (9.8) | 100% | ⚠ Explotación activa | 3 abr 2025 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to… |
| CVE-2024-38657 | Media (4.9) | 1.6% | — | 21 feb 2025 | External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files. |
| CVE-2025-22467 | Alta (8.8) | 4.7% | — | 11 feb 2025 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution. |
| CVE-2024-13843 | Media (4.4) | 0.36% | — | 11 feb 2025 | Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data. |
| CVE-2024-13842 | Media (4.4) | 0.32% | — | 11 feb 2025 | A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data. |
| CVE-2024-13830 | Media (6.1) | 0.74% | — | 11 feb 2025 | Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required. |
| CVE-2024-12058 | Media (4.9) | 1.1% | — | 11 feb 2025 | External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files. |
| CVE-2024-10644 | Alta (7.2) | 2.8% | — | 11 feb 2025 | Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution. |
| CVE-2025-0283 | Alta (7) | 17% | — | 8 ene 2025 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.