Missing Authorization Vulnerability in Ivanti Connect Secure and Related Products
CVE-2025-55142
8.8HIGH
Key Information:
- Vendor
Ivanti
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-55142?
A missing authorization vulnerability in Ivanti Connect Secure and associated products allows a remote authenticated attacker with read-only admin privileges to change critical authentication-related settings. This could potentially lead to unauthorized access or modification of sensitive configurations. The flaw affects various versions of Ivanti products, emphasizing the urgency for users to apply security updates promptly. A fix was released on August 2, 2025.
Affected Version(s)
Connect Secure 22.7R2.9
Neurons for Secure Access 22.8R1.4 (Fix deployed on 02-Aug-2025)
Policy Secure 22.7R1.6