vendor:
Connect Secure
by:
absholi7ly
6.1
CVSS
HIGH
Remote Code Execution (RCE)
94
CWE
Product Name: Connect Secure
Affected Version From: 22.7R2.5
Affected Version To: 22.7R2.5
Patch Exists: NO
Related CWE: CVE-2025-0282
CPE: a:ivanti:connect_secure:22.7R2.5
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=12403, https://www.infosecmatter.com/nessus-plugin-library/?id=56051, https://www.infosecmatter.com/nessus-plugin-library/?id=118963, https://www.infosecmatter.com/nessus-plugin-library/?id=120435, https://www.infosecmatter.com/nessus-plugin-library/?id=52701, https://www.infosecmatter.com/nessus-plugin-library/?id=52629, https://www.infosecmatter.com/nessus-plugin-library/?id=52702, https://www.infosecmatter.com/nessus-plugin-library/?id=65100, https://www.infosecmatter.com/nessus-plugin-library/?id=118277, https://www.infosecmatter.com/nessus-plugin-library/?id=141332
Platforms Tested:
2025
Ivanti Connect Secure 22.7R2.5 – Remote Code Execution (RCE)
The Ivanti Connect Secure version 22.7R2.5 is vulnerable to remote code execution. By crafting a specific payload, an attacker can exploit this vulnerability to execute arbitrary commands on the target system. This vulnerability has been assigned the CVE-2025-0282.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version provided by the vendor.