CVE-2025-5450
Last modified
CVE-2025-5450 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin with read-only rights to modify settings that should be restricted.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin with read-only rights to modify settings that should be restricted.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Connect Secure | < 22.7 |
| Ivanti | Connect Secure | 22.7 |
| Ivanti | Policy Secure | < 22.7 |
| Ivanti | Policy Secure | 22.7 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-5450?
How severe is CVE-2025-5450?
How do I fix CVE-2025-5450?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-54493A stack-based buffer overflow vulnerability exists in the MF…9.8
- CVE-2025-54494A stack-based buffer overflow vulnerability exists in the MF…9.8
- CVE-2025-54495A reflected cross-site scripting (xss) vulnerability exists …5.4
- CVE-2025-54496A maliciously crafted project file may cause a heap-based bu…8.4
- CVE-2025-54497Cognex In-Sight Explorer and In-Sight Camera Firmware expose…8.1
- CVE-2025-54499Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fa…3.7
- CVE-2025-54500An HTTP/2 implementation flaw allows a denial-of-service (Do…5.3
- CVE-2025-54502Incorrect use of boot service in the AMD Platform Configurat…7.5
- CVE-2025-54505A transient execution vulnerability within AMD CPUs may allo…2
- CVE-2025-54509Improper access control for register interface in the Input-…4
- CVE-2025-5451A stack-based buffer overflow in Ivanti Connect Secure befor…4.9
- CVE-2025-54510A missing lock verification in AMD Secure Processor (ASP) fi…5.9
Are you affected by CVE-2025-5450?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
