Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-55145

CVE-2025-55145: Ivanti Neurons Auth Bypass Vulnerability

CVE-2025-55145 is an authentication bypass flaw in Ivanti Neurons for Secure Access that allows authenticated attackers to hijack HTML5 connections. This article covers technical details, affected versions, and mitigations.

Published:

CVE-2025-55145 Overview

CVE-2025-55145 is a missing authorization vulnerability [CWE-862] affecting multiple Ivanti remote access products. The flaw resides in HTML5 connection handling and allows a remote authenticated attacker to hijack existing HTML5 sessions established by other users. Successful exploitation requires user interaction and grants the attacker access to confidentiality and integrity of in-flight sessions with limited availability impact.

Affected products include Ivanti Connect Secure, Ivanti Policy Secure, Ivanti ZTA Gateway, and Ivanti Neurons for Secure Access. Ivanti addressed the issue in its September Security Advisory, with the cloud-side fix for Neurons for Secure Access deployed on 02-Aug-2025.

Critical Impact

An authenticated remote attacker can hijack active HTML5 connections on unpatched Ivanti gateways, exposing user sessions and the data transiting them.

Affected Products

  • Ivanti Connect Secure before 22.7R2.9 or 22.8R2
  • Ivanti Policy Secure before 22.7R1.6
  • Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4

Discovery Timeline

  • 2025-09-09 - CVE-2025-55145 published to NVD
  • 2025-09-24 - Last updated in NVD database

Technical Details for CVE-2025-55145

Vulnerability Analysis

The vulnerability is a missing authorization weakness in the HTML5 connection handling logic of Ivanti's remote access gateways. HTML5 access in these products provides browser-based RDP, SSH, and Telnet sessions through the gateway. The affected code paths do not properly verify that the requesting authenticated user owns the HTML5 connection being accessed.

As a result, an authenticated user can take over HTML5 sessions established by other users. Because the vulnerability changes scope (S:C in the CVSS vector), the impact extends beyond the attacker's own security context to other users connected through the same gateway. The attacker gains the ability to view and manipulate data within the hijacked session, including credentials entered during the session and any resources the legitimate user accessed.

User interaction is required, meaning the attacker must induce a victim to interact with crafted content or perform a triggering action. Exploitation does not require administrative privileges, only valid authenticated access to the gateway.

Root Cause

The root cause is the absence of an authorization check binding HTML5 connection identifiers to the authenticated user that established them. Without that ownership validation, the server accepts requests referencing another user's connection and routes session traffic to the attacker.

Attack Vector

The attack is network-based. An authenticated attacker on the gateway issues requests targeting HTML5 connection objects owned by other authenticated users. Combined with social engineering or pre-positioned content that triggers the required user interaction, the attacker pivots into the victim's HTML5 session and observes or hijacks its contents.

No verified public proof-of-concept is available. The vulnerability mechanism is described in the Ivanti September Security Advisory.

Detection Methods for CVE-2025-55145

Indicators of Compromise

  • HTML5 session activity associated with a user account originating from an unexpected source IP, geolocation, or device fingerprint.
  • Concurrent or overlapping HTML5 sessions for the same connection identifier referenced by more than one authenticated principal.
  • Unexpected RDP, SSH, or Telnet command activity inside HTML5 sessions that does not match the legitimate user's behavioral baseline.

Detection Strategies

  • Correlate gateway authentication events with HTML5 session establishment and access events to identify sessions accessed by accounts other than the establishing user.
  • Alert on HTML5 connection access requests that reference connection IDs not previously created by the requesting session.
  • Baseline normal HTML5 usage per user, then flag deviations such as off-hours access, source IP changes mid-session, or sudden bursts of session enumeration.

Monitoring Recommendations

  • Forward Ivanti Connect Secure, Policy Secure, ZTA Gateway, and Neurons for Secure Access logs to a centralized SIEM with retention sufficient for retrospective analysis.
  • Monitor administrative interfaces and audit logs for new or modified HTML5 bookmarks and resource profiles that could be used to lure victims into triggering user interaction.
  • Track patch and version state across all gateway appliances to confirm none remain on vulnerable releases.

How to Mitigate CVE-2025-55145

Immediate Actions Required

  • Upgrade Ivanti Connect Secure to 22.7R2.9 or 22.8R2, Ivanti Policy Secure to 22.7R1.6, and Ivanti ZTA Gateway to 2.8R2.3-723 or later.
  • Verify that Ivanti Neurons for Secure Access tenants are running 22.8R1.4 or later; the cloud-side fix was deployed on 02-Aug-2025.
  • Review authentication and HTML5 session logs for activity consistent with session hijacking since the vulnerable versions were deployed.

Patch Information

Ivanti published fixed builds in its September Security Advisory. Refer to the Ivanti Security Advisory September for the complete list of fixed versions and upgrade instructions. Neurons for Secure Access was remediated by Ivanti on 02-Aug-2025; on-premises products require customer-driven upgrades.

Workarounds

  • Restrict HTML5 access to only the user populations that require it, and disable HTML5 bookmarks on roles where they are not necessary.
  • Enforce multi-factor authentication and short session lifetimes to limit the window in which an authenticated attacker can target other users' HTML5 connections.
  • Limit administrative access to the gateway and review which authenticated users can reach the HTML5 service until patching is complete.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.