CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2025-0282

CVSS 9.0v3.1pub. 2025-01-08upd. 2026-08-04

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

🤖 AI Analysis
How it works

An attacker sends a specially crafted network request to the vulnerable device without needing any credentials. Exceeding the allowed data size written to the stack (stack-based buffer overflow, CWE-121, CWE-787) leads to overwriting memory areas beyond the intended buffer. This results in seizing control over the program execution flow and enables execution of arbitrary code (RCE) with the privileges of the process handling the connection.

Impact

An attacker can gain full control over the vulnerable device — execute arbitrary code, modify configuration, steal user credentials or use the compromised device as an entry point for further actions in the organization's network.

Mitigation & patch

Products must be updated immediately to the following versions: Ivanti Connect Secure to version 22.7R2.5 or later, Ivanti Policy Secure to version 22.7R1.2 or later, Ivanti Neurons for ZTA gateways to version 22.7R2.3 or later. Detailed vulnerability mitigation instructions are available in Ivanti's official security advisory and CISA guidelines at the address indicated in the references.

Who is affected

Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, Ivanti Neurons for ZTA gateways before version 22.7R2.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Ivanti Connect Secure

    APP
    Ivanti
    22.7
  • Ivanti Neurons For Zero Trust Access

    APP
    Ivanti
    22.7
  • Ivanti Policy Secure

    APP
    Ivanti
    22.7

CISA KEV — detailsi

Vendori
Ivanti
Producti
Connect Secure, Policy Secure, and ZTA Gateways
Added to KEVi
January 8, 2025
Remediation deadline (US Federal)i
January 15, 2025(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.

CISA descriptioni

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 15 stycznia 2025
Tags
RCEAuth BypassMemory
CWE
References

Related vulnerabilities

CVE-2025-22457CRITICAL9.0⚠ KEVPL ✓same product

Stack-based buffer overflow w Ivanti Connect Secure, Policy Secure i ZTA Gateways umożliwiający RCE

CVE-2024-21887CRITICAL9.1⚠ KEVPL ✓same product

Command injection w Ivanti Connect Secure i Policy Secure — RCE jako administrator

CVE-2021-22893CRITICAL10.0⚠ KEVPL ✓same product

Ivanti/Pulse Connect Secure — krytyczny auth bypass umożliwiający RCE

CVE-2019-11510CRITICAL10.0⚠ KEVPL ✓same product

Krytyczny path traversal w Pulse Connect Secure — odczyt dowolnych plików bez uwierzytelnienia

CVE-2024-10644CRITICAL9.1PL ✓same product

Code injection w Ivanti Connect Secure i Policy Secure — RCE