CVE-2025-0282
CRITICAL KEV RANSOMWARE NUCLEIIvanti Connect Secure <22.7R2.5 - RCE
Title source: llmDescription
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
Exploits (14)
exploitdb
WORKING POC
by Abdualhadi khalifa · pythonremotemultiple
https://www.exploit-db.com/exploits/52213
nomisec
WORKING POC
52 stars
by absholi7ly · poc
https://github.com/absholi7ly/CVE-2025-0282-Ivanti-exploit
nomisec
WORKING POC
5 stars
by Hexastrike · poc
https://github.com/Hexastrike/Ivanti-Connect-Secure-Logs-Parser
nomisec
SUSPICIOUS
3 stars
by AnonStorks · poc
https://github.com/AnonStorks/CVE-2025-0282-Full-version
metasploit
WORKING POC
GREAT
by Stephen Fewer, Christophe De La Fuente · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ivanti_connect_secure_stack_overflow_rce_cve_2025_22457.rb
Nuclei Templates (1)
Ivanti Connect Secure - Stack-based Buffer Overflow
CRITICALVERIFIEDby ritikchaddha
Shodan:
http.title:"ivanti connect secure"
References (7)
Scores
CVSS v3
9.0
EPSS
0.9413
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CISA KEV
2025-01-08
VulnCheck KEV
2025-01-08
ENISA EUVD
EUVD-2025-1580
Ransomware Use
Confirmed
CWE
CWE-121
CWE-787
Status
published
Products (3)
ivanti/connect_secure
22.7 r2 (5 CPE variants)
ivanti/neurons_for_zero-trust_access
22.7 r2 (3 CPE variants)
ivanti/policy_secure
22.7 r1 (3 CPE variants)
Published
Jan 08, 2025
KEV Added
Jan 08, 2025
Tracked Since
Feb 18, 2026