VDB
CVE-2025-55145
CVE-2025-55145
PUBLISHED
De multiples vulnérabilités ont été découvertes dans les produits Ivanti. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
EPSS 0.57% · 69.0th percentile
Risk Scores
EPSS Score
0.57%
69.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Zero Trust Access gateways | |
| Ivanti | Neurons | |
| Ivanti | Connect Secure (ICS) | |
| Ivanti | Policy Secure (IPS) | |
| Ivanti | Endpoint Manager (EPM) |
Timeline
- Sep 9, 2025 Coalition ESS Score
- Sep 9, 2025 CVE Published
- Sep 10, 2025 EPSS Score
- Sep 17, 2025 EPSS Score
- Sep 25, 2025 EPSS Score
- Oct 2, 2025 EPSS Score
- Oct 4, 2025 Coalition ESS Score
- Oct 6, 2025 Coalition ESS Score
- Oct 9, 2025 EPSS Score
- Oct 17, 2025 EPSS Score
- Oct 24, 2025 EPSS Score
- Oct 31, 2025 EPSS Score
References
- https://cert.ssi.gouv.fr/avis/CERTFR-2025-AVI-0768/ advisory
- https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs advisory
- https://www.ivanti.com/blog/september-2025-security-update advisory
- https://forums.ivanti.com/s/article/Security-Advisory-September-2025-for-Ivanti-EPM-2024-SU3-and-EPM-2022-SU8 advisory