CVE-2025-0282: Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
Other sources
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Connect Secureto a version that resolves this vulnerability.Fixed in 22.7R2.5 - Upgrade
Upgrade
Ivanti Policy Secureto a version that resolves this vulnerability.Fixed in 22.7R1.2 - Upgrade
Upgrade
Ivanti Neurons for ZTA gatewaysto a version that resolves this vulnerability.Fixed in 22.7R2.3 - Compensating control
Conduct hunt activities to identify any exploitation attempts related to the unauthenticated remote code execution stack-based buffer overflow prior to returning the device to service.
- Operational
Take remediation actions if the hunt activities identify indicators of compromise, and apply updates prior to returning the affected device(s) to service.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0282?
CVE-2025-0282 is classified as a critical vulnerability due to its potential for remote code execution by unauthenticated attackers.
How do I fix CVE-2025-0282?
To fix CVE-2025-0282, upgrade Ivanti Connect Secure, Policy Secure, or Neurons for ZTA gateways to the latest versions specified in the security advisory.
Which versions are affected by CVE-2025-0282?
CVE-2025-0282 affects Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3.
Can CVE-2025-0282 be exploited remotely?
Yes, CVE-2025-0282 can be exploited remotely by unauthenticated attackers to execute arbitrary code.
Is it safe to use affected Ivanti products until CVE-2025-0282 is patched?
No, using affected versions of Ivanti products poses a security risk and should be avoided until they are patched.