CVE-2025-0282

CRITICAL KEV RANSOMWARE NUCLEI

Ivanti Connect Secure <22.7R2.5 - RCE

Title source: llm

Description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

Exploits (14)

exploitdb WORKING POC
by Abdualhadi khalifa · pythonremotemultiple
https://www.exploit-db.com/exploits/52213
nomisec WORKING POC 52 stars
by absholi7ly · poc
https://github.com/absholi7ly/CVE-2025-0282-Ivanti-exploit
nomisec WORKING POC 49 stars
by sfewer-r7 · remote
https://github.com/sfewer-r7/CVE-2025-0282
nomisec WORKING POC 31 stars
by watchtowrlabs · poc
https://github.com/watchtowrlabs/CVE-2025-0282
nomisec WORKING POC 5 stars
by Hexastrike · poc
https://github.com/Hexastrike/Ivanti-Connect-Secure-Logs-Parser
nomisec WORKING POC 3 stars
by punitdarji · poc
https://github.com/punitdarji/Ivanti-CVE-2025-0282
nomisec SUSPICIOUS 3 stars
by AnonStorks · poc
https://github.com/AnonStorks/CVE-2025-0282-Full-version
nomisec SCANNER 2 stars
by AdaniKamal · poc
https://github.com/AdaniKamal/CVE-2025-0282
nomisec WORKING POC 2 stars
by almanatra · remote
https://github.com/almanatra/CVE-2025-0282
nomisec SCANNER 1 stars
by rxwx · poc
https://github.com/rxwx/pulse-meter
nomisec WORKING POC
by gmh5225 · poc
https://github.com/gmh5225/Blackash-CVE-2025-0282
metasploit WORKING POC GREAT
by Stephen Fewer, Christophe De La Fuente · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ivanti_connect_secure_stack_overflow_rce_cve_2025_22457.rb

Nuclei Templates (1)

Ivanti Connect Secure - Stack-based Buffer Overflow
CRITICALVERIFIEDby ritikchaddha
Shodan: http.title:"ivanti connect secure"

Scores

CVSS v3 9.0
EPSS 0.9413
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CISA KEV 2025-01-08
VulnCheck KEV 2025-01-08
ENISA EUVD EUVD-2025-1580
Ransomware Use Confirmed
CWE
CWE-121 CWE-787
Status published
Products (3)
ivanti/connect_secure 22.7 r2 (5 CPE variants)
ivanti/neurons_for_zero-trust_access 22.7 r2 (3 CPE variants)
ivanti/policy_secure 22.7 r1 (3 CPE variants)
Published Jan 08, 2025
KEV Added Jan 08, 2025
Tracked Since Feb 18, 2026