{"id":"CVE-2025-22457","title":"A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code…","summary":"A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code…","severity":"critical","cvss":9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-121","CWE-787"],"vendor":"ivanti","product":"connect_secure","affected":["connect_secure < 22.7","connect_secure = 22.7","policy_secure < 22.7","policy_secure = 22.7","zero_trust_access_gateway < 22.8","zero_trust_access_gateway = 22.8"],"patched":["connect_secure 22.7","policy_secure 22.7","zero_trust_access_gateway 22.8"],"published":"2025-04-03","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-22457","references":[{"url":"https://forums.ivanti.com/s/article/April-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-22457","label":"3c1d8aa1-5a33-4ea4-8992-aadd6440af75"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-22457","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.99981,"epssPercentile":0.99981,"kev":true,"kevDateAdded":"2025-04-04","kevDueDate":"2025-04-11","kevRansomware":true,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-04T05:36:12.946Z","exploits":{"github":5,"githubRepos":["https://github.com/Vinylrider/ivantiunlocker","https://github.com/sfewer-r7/CVE-2025-22457","https://github.com/securekomodo/CVE-2025-22457"],"metasploit":["exploit/linux/http/ivanti_connect_secure_stack_overflow_rce_cve_2025_22457"],"checkedAt":"2026-09-11T03:07:18.926Z"},"exploitAvailable":true,"slug":"CVE-2025-22457","body":"## Overview\n\nA stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.\n\n## Affected\n\n- `connect_secure < 22.7`\n- `connect_secure = 22.7`\n- `policy_secure < 22.7`\n- `policy_secure = 22.7`\n- `zero_trust_access_gateway < 22.8`\n- `zero_trust_access_gateway = 22.8`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `connect_secure 22.7`\n- `policy_secure 22.7`\n- `zero_trust_access_gateway 22.8`","depth":"hadal","depthScore":99,"depthScoreParts":{"impact":49.5,"likelihood":20,"exploitation":25,"ransomware":5},"changes":[{"seq":4792,"id":"CVE-2025-22457","ts":1788887207105,"field":"exploit_available","old":"false","new":"true"},{"seq":3675,"id":"CVE-2025-22457","ts":1788886324144,"field":"exploit_available","old":"true","new":"false"},{"seq":2526,"id":"CVE-2025-22457","ts":1788883001534,"field":"exploit_available","old":"false","new":"true"},{"seq":1555,"id":"CVE-2025-22457","ts":1788882405369,"field":"exploit_available","old":"true","new":"false"},{"seq":669,"id":"CVE-2025-22457","ts":1788881843159,"field":"exploit_available","old":"false","new":"true"}]}