CVE-2025-0282
A critical vulnerability in Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways allows remote attackers to execute arbitrary code without authentication. The flaw is a stack-based buffer overflow that can be triggered over the network. It affects versions before 22.7R2.5, 22.7R1.2, and 22.7R2.3 respectively.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for Zero Trust Access gateways, all versions 22.7 and earlier (before 22.7R2.5, 22.7R1.2, and 22.7R2.3). Typical users are organizations deploying these products for secure remote access and zero‑trust networking.
Real-world impact
An attacker could run arbitrary code on the affected system, potentially taking full control, stealing data, or using the device as a foothold for further attacks.
Why this severity
The CVSS score of 9 reflects the high impact of remote code execution (confidentiality, integrity, availability all high) combined with the difficulty of exploitation (high attack complexity) but no user interaction or authentication required.
What to do about it
- 01Upgrade Ivanti Connect Secure to version 22.7R2.5 or later.
- 02Upgrade Ivanti Policy Secure to version 22.7R1.2 or later.
- 03Upgrade Ivanti Neurons for ZTA gateways to version 22.7R2.3 or later.
- 04Restart the affected services after the update.
- ›Conduct hunt activities to identify compromised devices.
- ›Isolate affected devices until the update is applied.
CISA KEV required action
Timeline
- Jan 8, 2025 · Jan 8, 2025Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jan 8, 2025 · Jan 8, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jan 15, 2025 · Jan 15, 2025CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- forums.ivanti.com/s/article/Security-Advisory…vendor advisory
- cloud.google.com/blog/topics/threat-intellig…exploittechnical description
- cisa.gov/cisa-mitigation-instruction…third party advisoryus government resource
- github.com/sfewer-r7/CVE-2025-0282exploit
- labs.watchtowr.com/exploitation-walkthrough-an…exploitthird party advisory
- cisa.gov/known-exploited-vulnerabili…us government resource
- cisa.gov/known-exploited-vulnerabili…us government resource