Reflected Text Injection in Ivanti Connect Secure and Other Ivanti Products
CVE-2025-55143

6.1MEDIUM

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
9 September 2025

What is CVE-2025-55143?

A reflected text injection vulnerability exists in Ivanti Connect Secure and multiple Ivanti products, allowing remote unauthenticated attackers to inject arbitrary text into an HTTP response. Although user interaction is required to exploit this issue, it poses significant risks if successfully executed. This affects various versions of Ivanti’s security solutions, with fixes deployed as of August 2, 2025. Users should ensure their products are updated to the latest versions to mitigate these risks.

Affected Version(s)

Connect Secure 22.7R2.9

Neurons for Secure Access 22.8R1.4 (Fix deployed on 02-Aug-2025)

Policy Secure 22.7R1.6

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.