CVE-2025-55147

8.8

Ivanti · Connect Secure, Policy Secure, ZTA Gateway, Neurons for Secure Access

A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple Ivanti products, allowing an unauthenticated remote attacker to perform sensitive actions on behalf of an authenticated user.

Executive summary

A critical CSRF vulnerability in Ivanti security gateways permits unauthenticated remote attackers to execute unauthorized actions on behalf of authenticated users, posing a significant risk to system integrity.

Vulnerability

This vulnerability is a Cross-Site Request Forgery (CWE-352) that allows an unauthenticated attacker to manipulate a victim into executing unauthorized administrative or sensitive operations. While the attacker does not require prior authentication, the attack requires user interaction to succeed.

Business impact

The exploitation of this vulnerability could lead to total loss of integrity and confidentiality, as attackers can perform sensitive actions within the context of an administrator or privileged user session. Given the CVSS score of 8.8, this flaw represents a high-risk entry point for unauthorized configuration changes or lateral movement. Failure to remediate may result in a complete compromise of the secure access environment, potentially impacting the entire corporate network.

Remediation

Immediate Action: Update all affected Ivanti appliances to the specified fixed versions immediately, as defined in the vendor security advisory.

Proactive Monitoring: Review system and access logs for unusual administrative requests or unexpected configuration changes that do not correlate with known authorized activity.

Compensating Controls: Implement strict Web Application Firewall (WAF) rules to filter suspicious requests and ensure that CSRF tokens are strictly validated across all sessions.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the affected Ivanti products must prioritize the application of the vendor-supplied patches to eliminate this CSRF vector. Given the privileged nature of these gateways, ensuring that all software is updated to the latest secure versions is critical to maintaining network perimeter security and preventing unauthorized administrative control.

More Ivanti CVEs

Sources