PT-2025-1027 · Ivanti · Ivanti Policy Secure+2

Published

2025-01-08

·

Updated

2026-04-14

·

CVE-2025-0283

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Connect Secure versions prior to 22.7R2.5 Ivanti Policy Secure versions prior to 22.7R1.2 Ivanti Neurons for ZTA gateways versions prior to 22.7R2.3
Description A stack-based buffer overflow exists in Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways. Successful exploitation of this issue allows a local authenticated attacker to escalate their privileges. The issue also allows a remote unauthenticated attacker to achieve remote code execution. The vulnerability enables attackers to gain administrator access, potentially allowing them to modify settings, passwords, and systems, and access sensitive information.
Recommendations Ivanti Connect Secure versions prior to 22.7R2.5 should be updated to version 22.7R2.5 or later. Ivanti Policy Secure versions prior to 22.7R1.2 should be updated to version 22.7R1.2 or later. Ivanti Neurons for ZTA gateways versions prior to 22.7R2.3 should be updated to version 22.7R2.3 or later.

Fix

LPE

Stack Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-00224
CVE-2025-0283

Affected Products

Ivanti Connect Secure
Ivanti Neurons For Zta Gateways
Ivanti Policy Secure