THREAT OPS › Threat News › [NVD] CVE-2025-22457 (CRITICAL 9.0) — A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
[NVD] CVE-2025-22457 (CRITICAL 9.0) — A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
CVE-2025-22457 CVSS: 9.0 CRITICAL Published: 2025-04-03T16:15:35.370
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
Indicators of compromise
- CVE-2025-22457cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-22457