Missing Authorization Vulnerability in Ivanti Connect Secure and Related Products
CVE-2025-55142

8.8HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
9 September 2025

What is CVE-2025-55142?

A missing authorization vulnerability in Ivanti Connect Secure and associated products allows a remote authenticated attacker with read-only admin privileges to change critical authentication-related settings. This could potentially lead to unauthorized access or modification of sensitive configurations. The flaw affects various versions of Ivanti products, emphasizing the urgency for users to apply security updates promptly. A fix was released on August 2, 2025.

Affected Version(s)

Connect Secure 22.7R2.9

Neurons for Secure Access 22.8R1.4 (Fix deployed on 02-Aug-2025)

Policy Secure 22.7R1.6

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.