CVE-2025-0283: Ivanti Connect Secure
High severity, CVSS 7.0. EPSS: 17.4% chance of exploitation in the next 30 days.
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.
Affected products
- Ivanti Connect Secure: before 9.1 (fixed in 9.1); from 22.2, before 22.7 (fixed in 22.7); version 9.1 only; version 21.9 only; version 21.12 only; version 22.1 only; …
- Ivanti Neurons For Zero-Trust Access: affected versions not specified; version 22.2 only; version 22.3 only; version 22.4 only; version 22.5 only; version 22.6 only; …
- Ivanti Policy Secure: before 22.7 (fixed in 22.7); version 22.7 only
Published 2025-01-08. Last modified 2026-06-17.