CVE-2025-55146
Last modified
CVE-2025-55146 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. An unchecked return value in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to trigger a denial of service.. EPSS estimates a 0.74% chance of exploitation in the next 30 days.
Description
An unchecked return value in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to trigger a denial of service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ivanti | Connect Secure | < 22.7 | — |
| Ivanti | Connect Secure | 22.7 | — |
| Ivanti | Policy Secure | < 22.7 | — |
| Ivanti | Policy Secure | 22.7 | — |
| Ivanti | Zero Trust Access Gateway | 22.8 | R2.2 |
| Ivanti | Neurons For Secure Access | < 22.8 | — |
| Ivanti | Neurons For Secure Access | 22.8 | R1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-55146?
How severe is CVE-2025-55146?
How do I fix CVE-2025-55146?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-5514Improper Handling of Length Parameter Inconsistency vulnerab…5.3
- CVE-2025-55141Missing authorization in Ivanti Connect Secure before 22.7R2…8.8
- CVE-2025-55142Missing authorization in Ivanti Connect Secure before 22.7R2…8.8
- CVE-2025-55143Reflected text injection in Ivanti Connect Secure before 22.…6.1
- CVE-2025-55144Missing authorization in Ivanti Connect Secure before 22.7R2…5.4
- CVE-2025-55145Missing authorization in Ivanti Connect Secure before 22.7R2…8.9
- CVE-2025-55147CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Iva…8.8
- CVE-2025-55148Missing authorization in Ivanti Connect Secure before 22.7R2…7.6
- CVE-2025-55149Tiny-Scientist is a lightweight framework for automating the…6.7
- CVE-2025-5515A vulnerability, which was classified as critical, has been …6.3
- CVE-2025-55150Stirling-PDF is a locally hosted web application that perfor…9.8
- CVE-2025-55151Stirling-PDF is a locally hosted web application that perfor…9.8
Are you affected by CVE-2025-55146?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
