logo

Critical vulnerabilities in Ivanti Connect Secure, Ivanti Policy Secure and Ivanti Neurons for ZTA Gateways

ID: 4fe48c4e-c051-53c4-bb8f-b6a5d1005c2d

STIX ID: report--4fe48c4e-c051-53c4-bb8f-b6a5d1005c2d

Feed Name: ASD's ACSC - Alerts RSS

Threat Score
85/100

Date Published: 2025-01-09

Date Updated: 2026-07-24

Author: Australian Cyber Security Centre (ACSC)

...
...

Ivanti and the Australian Cyber Security Centre (ACSC) have released an advisory about two stack-based buffer overflow vulnerabilities (CVE-2025-0282 and CVE-2025-0283) affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA Gateways; CVE-2025-0282 enables remote unauthenticated remote code execution and is actively exploited, while CVE-2025-0283 enables local privilege escalation. The advisory lists affected versions, recommends patching to fixed releases (e.g., Ivanti Connect Secure 22.7R2.5 or later), avoiding internet exposure of gateways, monitoring for suspicious activity, and provides contact information for assistance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.