CVE-2025-5468
Last modified
CVE-2025-5468 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files on disk.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files on disk.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ivanti | Connect Secure | < 22.7 | — |
| Ivanti | Connect Secure | 22.7 | — |
| Ivanti | Policy Secure | < 22.7 | — |
| Ivanti | Policy Secure | 22.7 | — |
| Ivanti | Zero Trust Access Gateway | 22.8 | R2.2 |
| Ivanti | Neurons For Secure Access | < 22.8 | — |
| Ivanti | Neurons For Secure Access | 22.8 | R1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-5468?
How severe is CVE-2025-5468?
How do I fix CVE-2025-5468?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-54674Cross-Site Request Forgery (CSRF) vulnerability in mklacroix…5.4
- CVE-2025-54675Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES …4.3
- CVE-2025-54676Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2025-54677Unrestricted Upload of File with Dangerous Type vulnerabilit…7.2
- CVE-2025-54678Improper Neutralization of Special Elements used in an SQL C…9.3
- CVE-2025-54679Missing Authorization vulnerability in vertim Neon Channel P…7.5
- CVE-2025-54680Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-54681URL Redirection to Untrusted Site ('Open Redirect') vulnerab…4.7
- CVE-2025-54682Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks…5.4
- CVE-2025-54683Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-54684Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-54685Insertion of Sensitive Information Into Sent Data vulnerabil…6.5
Are you affected by CVE-2025-5468?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
