Cyber Posture

CVE-2025-0283

High

Published: 08 January 2025

Published
08 January 2025
Modified
14 January 2025
KEV Added
Patch
CVSS Score 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.4511 97.6th percentile
Risk Priority 41 60% EPSS · 20% KEV · 20% CVSS

Description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.

Security Summary

CVE-2025-0283 is a stack-based buffer overflow vulnerability, associated with CWE-121 (Stack-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), affecting Ivanti Connect Secure versions prior to 22.7R2.5, Ivanti Policy Secure versions prior to 22.7R1.2, and Ivanti Neurons for ZTA gateways versions prior to 22.7R2.3. Published on January 8, 2025, it carries a CVSS v3.1 base score of 7.0 (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high confidentiality, integrity, and availability impacts under specific local access conditions.

A local authenticated attacker with low privileges can exploit this vulnerability due to its high attack complexity. Successful exploitation allows privilege escalation, enabling the attacker to gain elevated access on the affected systems.

Ivanti has issued a security advisory detailing patches for this issue, available at https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283. Mitigation involves upgrading to Ivanti Connect Secure 22.7R2.5 or later, Ivanti Policy Secure 22.7R1.2 or later, and Ivanti Neurons for ZTA gateways 22.7R2.3 or later.

Details

CWE(s)
CWE-121CWE-787

Affected Products

ivanti
connect secure
21.12, 21.9, 22.1, 22.7, 9.1 · ≤ 9.1 · 22.2 — 22.7
ivanti
neurons for zero-trust access
22.2, 22.3, 22.4, 22.5, 22.6
ivanti
policy secure
22.7 · ≤ 22.7

References