Skip to main content
CISA Known Exploited Vulnerabilities

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2025-01-08
Remediation due
2025-01-15
Ransomware
Known use

Required action
Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.

CISA notes
CISA Mitigation Instructions: https://www.cisa.gov/cisa-mitigation-instructions-CVE-2025-0282 Additional References: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283 ; https://nvd.nist.gov/vuln/detail/CVE-2025-0282

Description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

Severity

CVSS 3.1 · CNA9 CRITICAL
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC · CISA-ADP
Exploitationactive
Automatableno
Technical impacttotal

Affected Products

VendorProductAffected versions
IvantiConnect Secure
22.7R2 to 22.7R2.4
22.7R2.5 (unaffected)
IvantiPolicy Secure
22.7R1 to 22.7R1.2
IvantiNeurons for ZTA gateways
22.7R2 to 22.7R2.3
22.7R2.5 (unaffected)

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.