Critical vulnerabilities in Ivanti Connect Secure, Ivanti Policy Secure and Ivanti Neurons for ZTA Gateways
ID: 4fe48c4e-c051-53c4-bb8f-b6a5d1005c2d
STIX ID: report--4fe48c4e-c051-53c4-bb8f-b6a5d1005c2d
Feed Name: ASD's ACSC - Alerts RSS
Date Published: 2025-01-09
Date Updated: 2026-07-24
Author: Australian Cyber Security Centre (ACSC)
Ivanti and the Australian Cyber Security Centre (ACSC) have released an advisory about two stack-based buffer overflow vulnerabilities (CVE-2025-0282 and CVE-2025-0283) affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA Gateways; CVE-2025-0282 enables remote unauthenticated remote code execution and is actively exploited, while CVE-2025-0283 enables local privilege escalation. The advisory lists affected versions, recommends patching to fixed releases (e.g., Ivanti Connect Secure 22.7R2.5 or later), avoiding internet exposure of gateways, monitoring for suspicious activity, and provides contact information for assistance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
