📦 Zero Trust Access Gateway

by Ivanti

🔍 What is Zero Trust Access Gateway?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-22457

CRITICAL CVSS 9.0 Apr 3, 2025

A stack-based buffer overflow vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways allows remote unauthenticated attackers to execute arbitrary code on affected systems. This affect...

CVE-2025-55147

HIGH CVSS 8.8 Sep 9, 2025

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in multiple Ivanti security products that allows an unauthenticated remote attacker to trick authenticated users into performing se...

CVE-2025-55145

HIGH CVSS 8.9 Sep 9, 2025

This vulnerability allows authenticated remote attackers to hijack existing HTML5 connections in Ivanti secure access products. It affects organizations using Ivanti Connect Secure, Policy Secure, ZTA...

CVE-2025-55141

HIGH CVSS 8.8 Sep 9, 2025

This CVE describes a missing authorization vulnerability in Ivanti security products that allows authenticated users with read-only admin privileges to modify authentication settings. Attackers could ...

CVE-2025-5462

HIGH CVSS 7.5 Aug 12, 2025

A heap-based buffer overflow vulnerability in Ivanti secure access products allows remote unauthenticated attackers to trigger denial of service. This affects Ivanti Connect Secure, Policy Secure, ZTA...

CVE-2024-22024

HIGH CVSS 8.3 Feb 13, 2024

This XXE vulnerability in Ivanti's SAML implementation allows attackers to access restricted resources without authentication by processing malicious XML entities. It affects Ivanti Connect Secure, Iv...

CVE-2025-8711

MEDIUM CVSS 5.4 Sep 9, 2025

This is a Cross-Site Request Forgery (CSRF) vulnerability affecting multiple Ivanti secure access products. It allows remote unauthenticated attackers to perform limited actions on behalf of authentic...

CVE-2025-8712

MEDIUM CVSS 5.4 Sep 9, 2025

This CVE describes a missing authorization vulnerability in Ivanti secure access products that allows authenticated users with read-only admin privileges to modify restricted configuration settings. T...

CVE-2025-55144

MEDIUM CVSS 5.4 Sep 9, 2025

This CVE describes a missing authorization vulnerability in Ivanti secure access products that allows authenticated users with read-only admin privileges to modify restricted configuration settings. A...

CVE-2025-55143

MEDIUM CVSS 6.1 Sep 9, 2025

This reflected text injection vulnerability in Ivanti secure access products allows unauthenticated attackers to inject arbitrary text into HTTP responses. Attackers can craft malicious links that, wh...

CVE-2025-55139

MEDIUM CVSS 6.8 Sep 9, 2025

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in multiple Ivanti security products that allows authenticated administrators to enumerate internal services. Attackers with admin...

CVE-2025-5468

MEDIUM CVSS 5.5 Aug 12, 2025

This vulnerability allows authenticated local attackers to read arbitrary files on disk through improper symbolic link handling in Ivanti secure access products. It affects Ivanti Connect Secure, Poli...