CVSS v3.1 Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Prediction
Documented as more likely to be exploited than 98.0% of known CVEs.
Apr 04, 2025
Apr 11, 2025
Threat Analysis
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.
Remediation Directive
Apply mitigations as set forth in the CISA instructions linked below.
External Intelligence
CISA Advisory
https://www.cisa.gov/cisa-mitigation-instructions-cve-2025-22457
Additional References:
https://forums.ivanti.com/s/article/April-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-22457
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2025-22457