Missing Authorization Vulnerability in Ivanti Connect Secure and Related Products
CVE-2025-55142

8.8HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
9 September 2025

What is CVE-2025-55142?

A missing authorization vulnerability in Ivanti Connect Secure and associated products allows a remote authenticated attacker with read-only admin privileges to change critical authentication-related settings. This could potentially lead to unauthorized access or modification of sensitive configurations. The flaw affects various versions of Ivanti products, emphasizing the urgency for users to apply security updates promptly. A fix was released on August 2, 2025.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Connect Secure 22.7R2.9

Neurons for Secure Access 22.8R1.4 (Fix deployed on 02-Aug-2025)

Policy Secure 22.7R1.6

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.