CRITICAL
CVE-2025-0282
CVSS
9
KEV
Description
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
Summary dbcve.org
A stack-based buffer overflow vulnerability in Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways allows remote unauthenticated attackers to achieve remote code execution by overflowing a stack buffer.
Mitigation
Upgrade to Ivanti Connect Secure version 22.7R2.5, Ivanti Policy Secure version 22.7R1.2, or Ivanti Neurons for ZTA version 22.7R2.3 or later to remediate the vulnerability.
Weakness (CWE)
CWE-121
Stack-based Buffer Overflow
CWE-787
Out-of-bounds Write
EPSS Score
99.98%
Probability of exploitation in next 30 days
100th percentile
References
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283
Vendor Advisory
https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day
Exploit, Technical Description
https://www.cisa.gov/cisa-mitigation-instructions-cve-2025-0282
Third Party Advisory, US Government Resource
https://github.com/sfewer-r7/CVE-2025-0282
Exploit
https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-0282
US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-0282
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.