The vulnerabilities, identified by multiple CVEs, affect versions of ICS before 22.7R2.8 and IPS before 22.7R1.5.
According to Ivanti, there is no evidence of active exploitation in the wild at the time of disclosure.
Administrators are strongly urged to update to the latest versions—ICS 22.7R2.8 and IPS 22.7R1.5—available through the official Ivanti download portal.
The fixes are not backported to legacy 9.x versions, which have reached end-of-support as of December 31, 2024.
The advisory details six distinct vulnerabilities, each with unique technical characteristics and potential impact:
| CVE Number | Description | CVSS Score | CWE |
|---|---|---|---|
| CVE-2025-5450 | Improper access control in certificate management; allows read-only admins to modify restricted settings. | 6.3 | CWE-602 |
| CVE-2025-5451 | Stack-based buffer overflow; enables denial of service by remote authenticated admins. | 4.9 | CWE-121 |
| CVE-2025-5463 | Insertion of sensitive info into logs; local attackers may access confidential data. | 5.5 | CWE-532 |
| CVE-2025-5464 | Similar log file info leak, specific to ICS. | 6.5 | CWE-532 |
| CVE-2025-0293 | CLRF injection; allows remote admin to write to protected config files. | 6.6 | CWE-93 |
| CVE-2025-0292 | Server-Side Request Forgery (SSRF); remote admin can access internal network services. | 5.5 | CWE-918 |
Technical Terms Explained:
textCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
This indicates a network attack vector, low attack complexity, and limited impact on confidentiality, integrity, and availability.
Affected Versions:
Resolved Versions:
Customers are strongly encouraged to upgrade to the latest supported versions to maintain protection against these vulnerabilities.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant updates
The post Ivanti Connect Secure & Policy Secure Flaws Expose Systems to DoS Attacks appeared first on Cyber Security News.
If you're a Windows user who's looking for a PC version of the Apple Mac…
INDIANA, (WOWO): Voters across northeast Indiana will head to the polls on May 5, 2026,…
INDIANA, (WOWO): Voters across northeast Indiana will head to the polls on May 5, 2026,…
GRANT COUNTY, Ind. (WOWO): A 73-year-old man from Upland died Monday morning after a single-vehicle…
GRANT COUNTY, Ind. (WOWO): A 73-year-old man from Upland died Monday morning after a single-vehicle…
WHITLEY COUNTY, Ind.— Authorities have determined that a man who died following an officer-involved shooting…
This website uses cookies.