CVE-2025-5468
5.5MEDIUM
Key Information:
- Vendor
Ivanti
- Vendor
- CVE Published:
- 12 August 2025
What is CVE-2025-5468?
Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files on disk.
Affected Version(s)
Connect Secure 22.7R2.8
Neurons for Secure Access 22.8R1.4 (Fix deployed on 02-Aug-2025)
Policy Secure 22.7R1.5