Critical Ivanti Vulnerability CVE-2025-22457: What You Need to Know
Critical Ivanti Vulnerability CVE-2025-22457: What You Need to Know
A critical remote code execution (RCE) vulnerability (CVE-2025-22457) was found in Ivanti’s Connect Secure (ICS), Policy Secure, Pulse Connect Secure (PCS), and ZTA Gateways in April 2025. This vulnerability enables unauthenticated attackers to run arbitrary code on affected devices by utilising a stack-based buffer overflow in the X-Forwarded-For http request header. According to threat intelligence reports – UNC5221, a China-affiliated APT group, is actively exploiting this vulnerability to target the telecom, government, and defense industries.
In this blog, we’ll break down:
- What is CVE-2025-22457
- How Attackers exploit CVE-2025-22457
- Detection of Vulnerable Devices
- Mitigation strategies
- Conclusion
Read More »Critical Ivanti Vulnerability CVE-2025-22457: What You Need to Know