CNNVD-202509-1381 Information

CNNVD ID

CNNVD-202509-1381

CVE-2025-55143

  • CNNVD Published: 2025-09-09

Description (Chinese)

Ivanti Connect Secure(ICS)等都是美国Ivanti公司的产品。Ivanti Connect Secure是一款安全远程网络连接工具。Ivanti Policy Secure(IPS)是一个网络访问控制 (NAC) 解决方案。Ivanti Neurons for Secure是一个安全云技术平台。 Ivanti多款产品存在跨站脚本漏洞,该漏洞源于反射型文本注入,可能导致注入任意文本。以下产品及版本受到影响:Ivanti Connect Secure 22.7R2.9之前版本和22.8R2之前版本、Ivanti Policy Secure 22.7R1.6之前版本、Ivanti ZTA Gateway 2.8R2.3-723之前版本和Ivanti Neurons for Secure Access 22.8R1.4之前版本。

Description (English)

Ivanti Connect Security (ICS) and others are products of the American company Ivanti. Ivanti Contact Security is a secure remote network connection tool. Ivanti Policy Security is a web access control (NAC) solution. Ivanti Neurons for Security is a secure cloud technology platform. There was a cross-site script loophole in Ivanti ’ s multiple products, which stemmed from the injection of reflective text, which could lead to the injection of any text. The following products and versions were affected: the previous version of Ivanti Contact 22.7R2.9 and the previous version of 22.8R2, the previous version of Ivanti Policy 22.7R.1.6, the previous version of Ivanti ZTA Gateway 2.8R2.3-723 and the previous version of Ivanti Neurons for Security 22.8R1.4.

Hazard Level

High

Vulnerability Type

跨站脚本

Affected Vendor

Ivanti

Published

2025-09-09

Last Modified

2026-02-24

References

https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs?language=en_US https://vigilance.fr/vulnerability/Ivanti-Connect-Secure-multiple-vulnerabilities-dated-09-09-2025-48180

Patch

https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs?language=en_US

Share on: