CVE-2025-5451 Details
Description
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to trigger a denial of service.
A stack-based buffer overflow vulnerability has been identified in Ivanti Connect Secure (ICS) versions 22.7R2.7 and prior, as well as in Ivanti Policy Secure (IPS) versions 22.7R1.4 and prior. This vulnerability allows a remote authenticated attacker with administrative rights to cause a denial-of-service condition.
Users can upgrade to Ivanti Connect Secure version 22.7R2.8 or Ivanti Policy Secure version 22.7R1.5. These versions are available on the Ivanti Download Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://forums.ivanti.com/s/article/July-Security-Advisory-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Multiple-CVEs | ivanti | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti connect secure | < 22.7 22.7 - 22.7 r1 22.7 r1.1 22.7 r1.2 22.7 r1.3 22.7 r1.4 22.7 r1.5 22.7 r2 22.7 r2.1 22.7 r2.2 22.7 r2.3 22.7 r2.4 22.7 r2.5 22.7 r2.6 22.7 r2.7 |
CPE
Remediation
| |
| ivanti policy secure | < 22.7 22.7 - 22.7 r1 22.7 r1.1 22.7 r1.2 22.7 r1.3 22.7 r1.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2025 | Initial Analysis | [email protected] |
| Jul 8, 2025 | New CVE Received | ivanti |