Ivanti releases security updates for CVE-2025-22457 in its gateways.

Ivanti security update to address vulnerabilities in Ivanti Connect Secure, Policy Secure, and ZTA Gateways. Implement actions recommended by CISA to protect your systems.

martes, 8 de abril de 2025 • 3 min read • Q2BSTUDIO Team

Artificial-Intelligence-

Ivanti released security updates to address vulnerabilities (CVE-2025-22457) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways. A cyber threat actor could exploit CVE-2025-22457 to take control of an affected system.

CISA has added CVE-2025-22457 to its Known Exploited Vulnerabilities Catalog.

Consult the following resources for further guidance:

For any instance of Ivanti Connect Secure that has not been updated before February 28, 2025, to the latest Ivanti patch (22.7R2.6) and all instances of Pulse Connect Secure (EoS), Policy Secure, and ZTA Gateways, CISA urges users and administrators to implement the following actions:

  1. Perform threat hunting actions:
    1. Run an external Integrity Check Tool (ICT). For further guidance, see Ivanti's instructions.
    2. Perform threat hunting actions on any system connected to - or recently connected to - the affected Ivanti device.
  2. If threat hunting actions determine no compromise:
    1. For the highest level of confidence, perform a factory reset.
      1. For cloud and virtual systems, perform a factory reset using a known clean device image.
    2. Apply the patch described in the Ivanti Connect Secure, Policy Secure & ZTA Gateways Security Advisory (CVE-2025-22457). Note that patches for Ivanti ZTA Gateways and Ivanti Policy Secure will be available on April 19 and 21, respectively.
    3. Monitor authentication or identity management services that could be exposed.
    4. Continue auditing privileged access accounts.
  3. If threat hunting actions determine compromise:
    1. For devices confirmed compromised, isolate all affected instances from the network. Keep affected devices isolated until the following guidance is completed and patches are applied.
    2. Take a forensic image (including memory capture) or work with Ivanti to obtain a copy of the image.
    3. Disconnect all compromised instances.
    4. For the highest level of confidence, perform a factory reset.
      1. For cloud and virtual systems, perform a factory reset using a known clean device image.
    5. Revoke and reissue any connected or exposed certificates, keys, and passwords, including the following:
      1. Reset the admin enable password.
      2. Reset stored application programming interface (API) keys.
      3. Reset the password of any local user defined on the gateway, including service accounts used for authentication server configuration.
    6. If domain accounts associated with the affected products have been compromised:
      1. Reset passwords twice for local accounts, revoke Kerberos tickets, and then revoke tokens for cloud accounts in hybrid deployments.
      2. For cloud-joined/registered devices, disable the devices in the cloud to revoke device tokens.
    7. Apply the patch described in the Ivanti Connect Secure, Policy Secure & ZTA Gateways Security Advisory (CVE-2025-22457). Note that patches for Ivanti ZTA Gateways and Ivanti Policy Secure will be available on April 19 and 21, respectively.
    8. Report to CISA and Ivanti immediately.

Organizations should report incidents and anomalous activity to CISA's 24/7 Operations Center at Report@cisa.gov or (888) 282-0870.

Disclaimer: The information in this report is provided 'as is' for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoritism by CISA.

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.