CVE-2025-0282

CVSS 3.1 Score 9 of 10 (high)

Details

Published Jan 8, 2025
Updated: Mar 17, 2025
CWE ID 787
CWE ID 121

Summary

CVE-2025-0282 is a critical vulnerability affecting Ivanti Connect Secure versions before 22.7R2.5, Ivanti Policy Secure before 22.7R1.2, and Ivanti Neurons for ZTA gateways before 22.7R2.3. This issue results in a stack-based buffer overflow, which can be exploited by an unauthenticated attacker to execute arbitrary code remotely. Successful exploitation could lead to serious consequences, including data theft, system compromise, or unauthorized network access. Organizations using the affected Ivanti products are advised to upgrade to the latest versions to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ivanti Connect Secure
  • Ivanti Neurons For Zero-trust Access
  • Ivanti Policy Secure

Affected Vendors

  • Ivanti