CVE-2025-0282
Act now ● On CISA KEV — actively exploited used in ransomware
Actively exploited — on the CISA KEV list.
CVSS base
9.0
CRITICAL
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
100.0%
100.0th percentile
CISA KEV
Listed
Added 2025-01-08 · patch by 2025-01-15
Weakness / dates
CWE-787
Published 2025-01-08 · modified 2026-08-04
CVSS breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
| Attack Vector | N | Network |
| Attack Complexity | H | High |
| Privileges Required | N | None |
| User Interaction | N | None |
| Scope | C | Changed |
| Confidentiality | H | High |
| Integrity | H | High |
| Availability | H | High |
Timeline
- 2025-01-08 — Published (NVD)
- 2025-01-08 — Added to CISA KEV (actively exploited)
- 2025-01-15 — CISA patch-by deadline
- 2026-08-04 — Last modified (NVD)
Description
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
Affected
References
- https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283
- exploit https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day
- https://www.cisa.gov/cisa-mitigation-instructions-cve-2025-0282
- exploit https://github.com/sfewer-r7/CVE-2025-0282
- exploit https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-0282
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-0282