CVE-2025-55145
8.9Ivanti · Connect Secure, Policy Secure, ZTA Gateway, Neurons for Secure Access
A missing authorization vulnerability in multiple Ivanti products allows a remote authenticated attacker to hijack existing HTML5 connections.
Executive summary
A high-severity missing authorization flaw in multiple Ivanti products permits remote authenticated attackers to hijack active HTML5 sessions, potentially leading to full account compromise.
Vulnerability
The vulnerability is classified as CWE-862, Missing Authorization. It occurs within the HTML5 connection handling mechanism, allowing an authenticated attacker to perform unauthorized actions by hijacking active sessions.
Business impact
Successful exploitation poses a significant risk to organizational integrity, as session hijacking grants an attacker the same level of access as the victim. Given the CVSS score of 8.9, this vulnerability carries a high risk of unauthorized data access and potential lateral movement within the network. The ability to intercept and control active sessions undermines the security of remote access infrastructure, necessitating immediate attention.
Remediation
Immediate Action: Update all affected Ivanti products to the versions specified in the vendor advisory: Connect Secure (22.7R2.9 or 22.8R2), Policy Secure (22.7R1.6), ZTA Gateway (2.8R2.3-723), and Neurons for Secure Access (22.8R1.4).
Proactive Monitoring: Review administrative and user access logs for suspicious session activity, particularly unexpected HTML5 connection behaviors or concurrent logins from unusual locations.
Compensating Controls: Implement strict network segmentation and ensure that multi-factor authentication is enforced for all remote access points to limit the impact of potential session hijacking.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a critical risk to the security of remote access infrastructure. Administrators must prioritize the deployment of the provided patches across all affected Ivanti environments immediately. Failure to address this flaw could allow attackers to bypass security controls by hijacking established sessions, leading to unauthorized access to sensitive internal resources.