logo

Ivanti Security Update Addresses Severe Vulnerabilities in ICS, IPS, and ISAC (CVE-2025-22467, CVE-2024-38657, CVE-2024-10644)

ID: 631746f4-238e-5393-987c-82a5d8c64f92

STIX ID: report--631746f4-238e-5393-987c-82a5d8c64f92

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2025-02-13

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Ivanti has released security updates for Ivanti Connect Secure (ICS), Ivanti Policy Secure (IPS), and Ivanti Secure Access Client (ISAC) addressing several critical vulnerabilities—including CVE-2025-22467 (stack-based buffer overflow, CVSS 9.9), CVE-2024-10644 (code injection, CVSS 9.1) and CVE-2024-38657 (arbitrary file write, CVSS 9.1)—that could allow remote code execution or full system compromise; affected versions and recommended upgrades (ICS 22.7R2.6, IPS 22.7R1.3, ISAC 22.8R1) are listed and administrators are urged to apply patches immediately despite no reports of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.