A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
Is CVE-2025-0282 exploited?
Listed in the CISA KEV catalog on 2025-01-08.
Federal remediation due 2025-01-15.
Past that date by 623 days.
Used in ransomware campaigns.
EPSS puts exploitation in the next 30 days at 100.0%.
Public exploit code: proof of concept.
Public detection rules exist.
Which products and versions are affected?
Ivanti · Connect Secure · 22.7R2 - 22.7R2.4
Ivanti · Policy Secure · 22.7R1 - 22.7R1.2
Ivanti · Neurons for ZTA gateways · 22.7R2 - 22.7R2.3