Reflected Text Injection in Ivanti Connect Secure and Other Ivanti Products
CVE-2025-55143
6.1MEDIUM
Key Information:
- Vendor
Ivanti
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-55143?
A reflected text injection vulnerability exists in Ivanti Connect Secure and multiple Ivanti products, allowing remote unauthenticated attackers to inject arbitrary text into an HTTP response. Although user interaction is required to exploit this issue, it poses significant risks if successfully executed. This affects various versions of Ivanti’s security solutions, with fixes deployed as of August 2, 2025. Users should ensure their products are updated to the latest versions to mitigate these risks.
Affected Version(s)
Connect Secure 22.7R2.9
Neurons for Secure Access 22.8R1.4 (Fix deployed on 02-Aug-2025)
Policy Secure 22.7R1.6