← Back

CVE-2025-0282

Published: Jan 8, 2025Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.0
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 6.0
Source: NVD

Description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

Affected (11)

3 products
Connect Secure
Neurons For Zero Trust Access
Policy Secure
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 22.7 r2.1
Version 22.7 r2.2
Version 22.7 r2.3
Version 22.7 r2.4
Version 22.7 r2
Ivanti
Version 22.7 r2.2
Version 22.7 r2.3
Version 22.7 r2
Ivanti
Version 22.7 r1.1
Version 22.7 r1.2
Version 22.7 r1

References (7)

Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Exploit
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.