← Vulnerability feed

Vulnerability record · CVE-2025-0282 · published 8 January 2025

CVE-2025-0282: Ivanti Connect Secure stack buffer overflow enables unauthenticated RCE

Ivanti · Connect Secure

A stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated attacker execute code. The flaw is remotely reachable over the network and carries a CVSS 3.1 base score of 9.0 (critical). Because these are edge VPN/ZTNA appliances, successful exploitation gives an attacker a foothold inside the perimeter.

9.0 CVSS 3.1 Critical CISA KEV since 8 Jan 2025 Known ransomware use EPSS 100% · top 0.1% CWE-121 · Stack-based buffer overflowCWE-787 · Out-of-bounds write
9.0CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
7References, 3 tagged exploit
4 Aug 2026Last modified by NVD

Description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.0, unauthenticated network-reachable RCE on edge VPN/ZTNA appliances, KEV-listed with known ransomware use and near-maximum EPSS.

What it is

A stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated attacker execute code. The flaw is remotely reachable over the network and carries a CVSS 3.1 base score of 9.0 (critical). Because these are edge VPN/ZTNA appliances, successful exploitation gives an attacker a foothold inside the perimeter.

Impact

An attacker gains remote code execution on the gateway, which can lead to full compromise of the appliance and access to internal networks and credentials handled by it. CISA's KEV entry notes known ransomware campaign use, so downstream impact can include lateral movement and ransomware deployment.

Attack surface

Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any internet-exposed instance of the affected products is a candidate target. The only friction noted in the vector is high attack complexity (AC:H).

Exploitation

Listed in CISA KEV since 2025-01-08 with a 2025-01-15 remediation due date and flagged for known ransomware campaign use; EPSS 30-day probability is 0.99979 (99.98th percentile). Multiple references are tagged Exploit, including vendor-adjacent and third-party technical walkthroughs, indicating public exploitation detail exists.

What to do

  • Apply the vendor updates that move Connect Secure to 22.7R2.5 or later, Policy Secure to 22.7R1.2 or later, and Neurons for ZTA gateways to 22.7R2.3 or later.
  • Follow the CISA mitigation instructions, including conducting hunt activities and remediation before returning any device to service.
  • Until patched, remove or restrict internet exposure of affected gateways and enforce strict access controls on management interfaces.
  • Assume compromise for any unpatched, internet-facing instance and perform integrity checks and credential rotation before trusting the device again.
  • Monitor vendor and CISA advisories for updated guidance, as the KEV entry references additional mitigation steps.

Detection

  • Hunt for exploitation attempts and post-exploitation activity against Ivanti gateways using the technical indicators in the Google Cloud and WatchTowr analyses.
  • Review gateway logs for unexpected process execution, crashes, or anomalous child processes consistent with a buffer overflow and code execution.
  • Check for unauthorized configuration changes, new accounts, or persistence artifacts on the appliances, and validate system file integrity.
  • Correlate network telemetry for inbound requests to the vulnerable service from untrusted sources, especially around the KEV publication window.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-0282 to the Known Exploited Vulnerabilities catalog on 8 January 2025 as "Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service. Federal deadline 15 January 2025.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-0282 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed8.2CVE-2023-46805Ivanti Connect Secure and Policy Secure web component authentication bypassThe web component of Ivanti Connect Secure (ICS) 9.x and 22.x and Ivanti Policy Secure fails to properly enforce authentication, letting a remote att…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2025-0282), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.