Vulnerability record · CVE-2025-22457 · published 3 April 2025
CVE-2025-22457: Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCE
Ivanti · Connect Secure
A stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to execute code. The flaw is network-reachable with no privileges or user interaction required, and it is listed in CISA KEV with confirmed ransomware campaign use, making it a top-tier perimeter risk.
Description
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityRemote unauthenticated RCE on internet-facing security gateways, listed in CISA KEV with known ransomware use and an EPSS probability near 1.0.
What it is
A stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to execute code. The flaw is network-reachable with no privileges or user interaction required, and it is listed in CISA KEV with confirmed ransomware campaign use, making it a top-tier perimeter risk.
Impact
An attacker gains remote code execution on the gateway appliance, which typically sits at the network edge and can expose credentials, VPN sessions and internal network access. Successful exploitation can lead to full compromise of the device and lateral movement into protected environments.
Attack surface
Reached over the network via the affected gateway services; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed. Any internet-exposed Connect Secure, Policy Secure or ZTA Gateway instance is in scope.
Exploitation
CISA added it to KEV on 2025-04-04 with a 2025-04-11 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99981 (99.98th percentile), indicating active, near-certain exploitation.
What to do
- Apply the vendor patches: Connect Secure 22.7R2.6, Policy Secure 22.7R1.4 and ZTA Gateways 22.8R2.2 or later.
- Follow the CISA KEV required action and Ivanti April Security Advisory guidance, including any interim mitigations if patching is delayed.
- Remove or restrict internet exposure of affected gateways until patched, and enforce MFA and least-privilege access on remaining remote access paths.
- Assume compromise on unpatched, internet-facing appliances: rotate credentials and certificates, review sessions and reset devices per vendor guidance.
- Monitor vendor and CISA advisories for updated indicators and post-exploitation guidance.
Detection
- Hunt for crash or restart events and unexpected process terminations on Connect Secure, Policy Secure and ZTA Gateway appliances.
- Review appliance and upstream logs for anomalous HTTP requests or exploit attempts against gateway endpoints, especially from unfamiliar source IPs.
- Audit for unexpected new accounts, configuration changes, scheduled tasks or outbound connections originating from the gateway.
- Correlate gateway logs with authentication and VPN session records to spot post-exploitation access or lateral movement.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-22457 to the Known Exploited Vulnerabilities catalog on 4 April 2025 as "Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations as set forth in the CISA instructions linked below. Federal deadline 11 April 2025.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-22457 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-22457), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.