Critical severity9.0CISA KEVNVD Advisory· Published Jan 8, 2025· Updated Aug 4, 2026
CVE-2025-0282
CVE-2025-0282
Description
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17cpe:2.3:a:ivanti:connect_secure:22.7:r2.1:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:ivanti:connect_secure:22.7:r2.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.7:r2.2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.7:r2.3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.7:r2.4:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.7:r2:*:*:*:*:*:*
- (no CPE)range: <22.7R2.5
- (no CPE)range: 22.7R2
cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.7:r2.2:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.7:r2.2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.7:r2.3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.7:r2:*:*:*:*:*:*
cpe:2.3:a:ivanti:policy_secure:22.7:r1.1:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:ivanti:policy_secure:22.7:r1.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:22.7:r1.2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:policy_secure:22.7:r1:*:*:*:*:*:*
- (no CPE)range: <22.7R1.2
- (no CPE)range: 22.7R1
<22.7R2.3+ 1 more
- (no CPE)range: <22.7R2.3
- (no CPE)range: 22.7R2
Patches
Vulnerability mechanics
References
6- cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-daynvdExploitTechnical Description
- labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/nvdExploitThird Party Advisory
- forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283nvdVendor Advisory
- www.cisa.gov/cisa-mitigation-instructions-cve-2025-0282nvdThird Party AdvisoryUS Government Resource
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
1- LATAM Infrastructure Hit by Fortinet and Ivanti ExploitsInfosecurity Magazine · Jun 18, 2026