CVE-2025-0283
7.0
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.0 / Impact: 5.9
Source: NVD
Description
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.
Affected (83)
Products: Ivanti: Connect Secure, Neurons For Zero Trust Access, Policy Secure
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1 | |
| All versions | |
| Before 22.7 |
Related CWEs
CWE-121
Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (1)
Source: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
Vendor Advisory
Timeline
No history available yet.