📦 Policy Secure

by Ivanti

🔍 What is Policy Secure?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-22457

CRITICAL CVSS 9.0 Apr 3, 2025

A stack-based buffer overflow vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways allows remote unauthenticated attackers to execute arbitrary code on affected systems. This affect...

CVE-2024-10644

CRITICAL CVSS 9.1 Feb 11, 2025

This vulnerability allows remote authenticated administrators to inject malicious code into Ivanti Connect Secure and Policy Secure systems, leading to remote code execution. Organizations using affec...

CVE-2025-0282

CRITICAL CVSS 9.0 Jan 8, 2025

A stack-based buffer overflow vulnerability in Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways allows remote unauthenticated attackers to execute arbitrary code. This affects organi...

CVE-2024-39710

CRITICAL CVSS 9.1 Nov 13, 2024

This vulnerability allows authenticated administrators to inject malicious arguments into Ivanti Connect Secure and Policy Secure systems, leading to remote code execution. Attackers with admin creden...

CVE-2024-39712

CRITICAL CVSS 9.1 Nov 13, 2024

This vulnerability allows authenticated administrators to inject malicious arguments into Ivanti Connect Secure and Policy Secure systems, leading to remote code execution. Attackers with admin privil...

CVE-2024-38656

CRITICAL CVSS 9.1 Nov 13, 2024

This vulnerability allows remote authenticated attackers with admin privileges to execute arbitrary code on Ivanti Connect Secure and Policy Secure gateways through argument injection. Attackers can a...

CVE-2024-11005

CRITICAL CVSS 9.1 Nov 12, 2024

This CVE describes a command injection vulnerability in Ivanti Connect Secure and Policy Secure that allows authenticated administrators to execute arbitrary commands on the underlying system. Attacke...

CVE-2024-11007

CRITICAL CVSS 9.1 Nov 12, 2024

This CVE describes a command injection vulnerability in Ivanti Connect Secure and Ivanti Policy Secure that allows authenticated administrators to execute arbitrary commands on the underlying system. ...

CVE-2024-21894

CRITICAL CVSS 9.8 Apr 4, 2024

A heap overflow vulnerability in the IPSec component of Ivanti Connect Secure and Policy Secure gateways allows unauthenticated attackers to send specially crafted requests to crash the service, causi...

CVE-2024-21887

CRITICAL CVSS 9.1 Jan 12, 2024

This is a command injection vulnerability in Ivanti Connect Secure and Policy Secure gateways that allows authenticated administrators to execute arbitrary commands on the appliance. Attackers can cha...

CVE-2025-55147

HIGH CVSS 8.8 Sep 9, 2025

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in multiple Ivanti security products that allows an unauthenticated remote attacker to trick authenticated users into performing se...

CVE-2025-55145

HIGH CVSS 8.9 Sep 9, 2025

This vulnerability allows authenticated remote attackers to hijack existing HTML5 connections in Ivanti secure access products. It affects organizations using Ivanti Connect Secure, Policy Secure, ZTA...

CVE-2025-55141

HIGH CVSS 8.8 Sep 9, 2025

This CVE describes a missing authorization vulnerability in Ivanti security products that allows authenticated users with read-only admin privileges to modify authentication settings. Attackers could ...

CVE-2025-5462

HIGH CVSS 7.5 Aug 12, 2025

A heap-based buffer overflow vulnerability in Ivanti secure access products allows remote unauthenticated attackers to trigger denial of service. This affects Ivanti Connect Secure, Policy Secure, ZTA...

CVE-2024-37401

HIGH CVSS 7.5 Dec 12, 2024

An out-of-bounds read vulnerability in the IPsec implementation of Ivanti Connect Secure allows remote unauthenticated attackers to cause denial of service by crashing the service. This affects all Iv...

CVE-2024-38655

HIGH CVSS 7.2 Nov 13, 2024

This vulnerability allows remote authenticated attackers with admin privileges to execute arbitrary code on Ivanti Connect Secure and Policy Secure gateways through argument injection. Organizations u...

CVE-2024-9420

HIGH CVSS 8.8 Nov 12, 2024

A use-after-free vulnerability in Ivanti Connect Secure and Policy Secure allows authenticated remote attackers to execute arbitrary code on affected systems. This affects organizations using vulnerab...

CVE-2024-47906

HIGH CVSS 7.8 Nov 12, 2024

This vulnerability allows local authenticated attackers to escalate privileges on Ivanti Connect Secure and Policy Secure appliances. Attackers with existing local access can gain higher privileges th...

CVE-2024-22052

HIGH CVSS 7.5 Apr 4, 2024

A null pointer dereference vulnerability in the IPSec component of Ivanti Connect Secure and Policy Secure gateways allows unauthenticated attackers to send specially crafted requests that crash the s...

CVE-2024-22024

HIGH CVSS 8.3 Feb 13, 2024

This XXE vulnerability in Ivanti's SAML implementation allows attackers to access restricted resources without authentication by processing malicious XML entities. It affects Ivanti Connect Secure, Iv...

CVE-2024-21888

HIGH CVSS 8.8 Jan 31, 2024

This vulnerability allows authenticated users of Ivanti Connect Secure and Ivanti Policy Secure to escalate their privileges to administrator level. It affects all users of these products with standar...

CVE-2025-8711

MEDIUM CVSS 5.4 Sep 9, 2025

This is a Cross-Site Request Forgery (CSRF) vulnerability affecting multiple Ivanti secure access products. It allows remote unauthenticated attackers to perform limited actions on behalf of authentic...

CVE-2025-8712

MEDIUM CVSS 5.4 Sep 9, 2025

This CVE describes a missing authorization vulnerability in Ivanti secure access products that allows authenticated users with read-only admin privileges to modify restricted configuration settings. T...

CVE-2025-55144

MEDIUM CVSS 5.4 Sep 9, 2025

This CVE describes a missing authorization vulnerability in Ivanti secure access products that allows authenticated users with read-only admin privileges to modify restricted configuration settings. A...

CVE-2025-55143

MEDIUM CVSS 6.1 Sep 9, 2025

This reflected text injection vulnerability in Ivanti secure access products allows unauthenticated attackers to inject arbitrary text into HTTP responses. Attackers can craft malicious links that, wh...

CVE-2025-55139

MEDIUM CVSS 6.8 Sep 9, 2025

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in multiple Ivanti security products that allows authenticated administrators to enumerate internal services. Attackers with admin...

CVE-2025-5468

MEDIUM CVSS 5.5 Aug 12, 2025

This vulnerability allows authenticated local attackers to read arbitrary files on disk through improper symbolic link handling in Ivanti secure access products. It affects Ivanti Connect Secure, Poli...

CVE-2023-39339

MEDIUM CVSS 4.9 Jul 12, 2025

This vulnerability allows authenticated administrators on Ivanti Policy Secure to read arbitrary files through specially crafted web requests. It affects all versions below 22.6R1, potentially exposin...

CVE-2025-0292

MEDIUM CVSS 5.5 Jul 8, 2025

This SSRF vulnerability in Ivanti Connect Secure and Policy Secure allows authenticated administrators to make requests to internal network services from the vulnerable appliance. Attackers with admin...

CVE-2025-5463

MEDIUM CVSS 5.5 Jul 8, 2025

This vulnerability allows local authenticated attackers to access sensitive information that was improperly logged in Ivanti Connect Secure and Policy Secure systems. Attackers with valid local creden...

CVE-2025-5450

MEDIUM CVSS 6.3 Jul 8, 2025

This vulnerability allows authenticated administrators with read-only permissions to modify restricted settings in Ivanti Connect Secure and Ivanti Policy Secure. Attackers with compromised admin cred...

CVE-2024-38657

MEDIUM CVSS 4.9 Feb 21, 2025

This vulnerability allows remote authenticated attackers with admin privileges to write arbitrary files by controlling file names in Ivanti Connect Secure and Policy Secure. Attackers could potentiall...

CVE-2024-13830

MEDIUM CVSS 6.1 Feb 11, 2025

This reflected cross-site scripting (XSS) vulnerability in Ivanti Connect Secure and Policy Secure allows remote unauthenticated attackers to execute malicious scripts in victims' browsers. When explo...

CVE-2024-13843

MEDIUM CVSS 6.0 Feb 11, 2025

This vulnerability allows local authenticated administrators on Ivanti Connect Secure and Policy Secure systems to read sensitive data stored in cleartext. It affects organizations using these Ivanti ...

CVE-2024-12058

MEDIUM CVSS 6.8 Feb 11, 2025

This vulnerability allows remote authenticated attackers with admin privileges to read arbitrary files on Ivanti Connect Secure and Policy Secure appliances. Attackers can exploit external control of ...

CVE-2024-47909

MEDIUM CVSS 4.9 Nov 12, 2024

A stack-based buffer overflow vulnerability in Ivanti Connect Secure and Policy Secure allows remote authenticated administrators to cause denial of service. This affects organizations using these pro...