Security Advisory

CVE-2025-5468

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-08-12 15:05:23
Last updated 2025-08-12 18:58:34
Assigner ivanti
CVSS score 5.5
State PUBLISHED

Description

Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files on disk.