H-ISAC TLP White Threat Bulletin Ivanti Connect Secure Vulnerability Actively Exploited By China-Nexus Group
April 3, 2025
On April 3, 2025, Ivanti released a regarding the active exploitation of a critical security flaw affecting vulnerable Ivanti Connect Secure, Pulse Connect Secure, Policy Secure, and ZTA gateway products.
The vulnerability, tracked as CVE-2025-22457, has a CVSS critical score of 9.0 and is a stack-based buffer overflow flaw impacting Ivanti Connect Secure (22.7R2.5 and prior), Pulse Connect Secure (9.1R18.9 and prior) which reached end-of-support as of December 31, 2024, Ivanti Policy Secure (22.7R1.3 and prior), and ZTA Gateways (22.8R2 and prior).
Successful exploitation of the security flaw allows remote unauthenticated threat actors to gain remote code execution capabilities on vulnerable instances.
VIew the detailed report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact: