7

CVE-2025-0283

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Connect Secure Version < 9.1
Ivanti ≫ Connect Secure Version >= 22.2 < 22.7
Ivanti ≫ Connect Secure Version 9.1 Update -
Ivanti ≫ Connect Secure Version 9.1 Update r1
Ivanti ≫ Connect Secure Version 9.1 Update r1.0
Ivanti ≫ Connect Secure Version 9.1 Update r10
Ivanti ≫ Connect Secure Version 9.1 Update r10.0
Ivanti ≫ Connect Secure Version 9.1 Update r10.2
Ivanti ≫ Connect Secure Version 9.1 Update r11
Ivanti ≫ Connect Secure Version 9.1 Update r11.0
Ivanti ≫ Connect Secure Version 9.1 Update r11.1
Ivanti ≫ Connect Secure Version 9.1 Update r11.3
Ivanti ≫ Connect Secure Version 9.1 Update r11.4
Ivanti ≫ Connect Secure Version 9.1 Update r11.5
Ivanti ≫ Connect Secure Version 9.1 Update r12
Ivanti ≫ Connect Secure Version 9.1 Update r12.1
Ivanti ≫ Connect Secure Version 9.1 Update r12.2
Ivanti ≫ Connect Secure Version 9.1 Update r13
Ivanti ≫ Connect Secure Version 9.1 Update r13.1
Ivanti ≫ Connect Secure Version 9.1 Update r14
Ivanti ≫ Connect Secure Version 9.1 Update r14.4
Ivanti ≫ Connect Secure Version 9.1 Update r15
Ivanti ≫ Connect Secure Version 9.1 Update r15.2
Ivanti ≫ Connect Secure Version 9.1 Update r16
Ivanti ≫ Connect Secure Version 9.1 Update r16.1
Ivanti ≫ Connect Secure Version 9.1 Update r17
Ivanti ≫ Connect Secure Version 9.1 Update r17.1
Ivanti ≫ Connect Secure Version 9.1 Update r17.2
Ivanti ≫ Connect Secure Version 9.1 Update r18
Ivanti ≫ Connect Secure Version 9.1 Update r18.1
Ivanti ≫ Connect Secure Version 9.1 Update r18.2
Ivanti ≫ Connect Secure Version 9.1 Update r18.3
Ivanti ≫ Connect Secure Version 9.1 Update r18.7
Ivanti ≫ Connect Secure Version 9.1 Update r18.8
Ivanti ≫ Connect Secure Version 9.1 Update r18.9
Ivanti ≫ Connect Secure Version 9.1 Update r4.3
Ivanti ≫ Connect Secure Version 9.1 Update r8
Ivanti ≫ Connect Secure Version 21.9 Update r1
Ivanti ≫ Connect Secure Version 21.12 Update r1
Ivanti ≫ Connect Secure Version 22.1 Update r1
Ivanti ≫ Connect Secure Version 22.1 Update r6
Ivanti ≫ Connect Secure Version 22.7 Update -
Ivanti ≫ Connect Secure Version 22.7 Update r1
Ivanti ≫ Connect Secure Version 22.7 Update r1.1
Ivanti ≫ Connect Secure Version 22.7 Update r1.2
Ivanti ≫ Connect Secure Version 22.7 Update r1.3
Ivanti ≫ Connect Secure Version 22.7 Update r1.4
Ivanti ≫ Connect Secure Version 22.7 Update r1.5
Ivanti ≫ Connect Secure Version 22.7 Update r2
Ivanti ≫ Connect Secure Version 22.7 Update r2.1
Ivanti ≫ Connect Secure Version 22.7 Update r2.2
Ivanti ≫ Connect Secure Version 22.7 Update r2.3
Ivanti ≫ Connect Secure Version 22.7 Update r2.4
Ivanti ≫ Neurons For Zero-trust Access Version 22.2 Update r1
Ivanti ≫ Neurons For Zero-trust Access Version 22.2 Update r4
Ivanti ≫ Neurons For Zero-trust Access Version 22.2 Update r5
Ivanti ≫ Neurons For Zero-trust Access Version 22.3 Update r1
Ivanti ≫ Neurons For Zero-trust Access Version 22.3 Update r4
Ivanti ≫ Neurons For Zero-trust Access Version 22.4 Update r1
Ivanti ≫ Neurons For Zero-trust Access Version 22.4 Update r3
Ivanti ≫ Neurons For Zero-trust Access Version 22.5 Update r1
Ivanti ≫ Neurons For Zero-trust Access Version 22.5 Update r1.2
Ivanti ≫ Neurons For Zero-trust Access Version 22.6 Update r1
Ivanti ≫ Neurons For Zero-trust Access Version 22.6 Update r1.2
Ivanti ≫ Neurons For Zero-trust Access Version 22.6 Update r1.3
Ivanti ≫ Neurons For Zero-trust Access Version 22.6 Update r1.5
Ivanti ≫ Neurons For Zero-trust Access Version 22.6 Update r1.6
Ivanti ≫ Neurons For Zero-trust Access Version 22.6 Update r1.7
Ivanti ≫ Neurons For Zero-trust Access Version 22.7 Update r1
Ivanti ≫ Neurons For Zero-trust Access Version 22.7 Update r1.2
Ivanti ≫ Neurons For Zero-trust Access Version 22.7 Update r1.3
Ivanti ≫ Neurons For Zero-trust Access Version 22.7 Update r1.4
Ivanti ≫ Neurons For Zero-trust Access Version 22.7 Update r1.5
Ivanti ≫ Neurons For Zero-trust Access Version 22.7 Update r1.6
Ivanti ≫ Neurons For Zero-trust Access Version 22.7 Update r2
Ivanti ≫ Neurons For Zero-trust Access Version 22.7 Update r2.2
Ivanti ≫ Neurons For Zero-trust Access Version 22.7 Update r2.3
Ivanti ≫ Policy Secure Version < 22.7
Ivanti ≫ Policy Secure Version 22.7 Update -
Ivanti ≫ Policy Secure Version 22.7 Update r1
Ivanti ≫ Policy Secure Version 22.7 Update r1.1
Ivanti ≫ Policy Secure Version 22.7 Update r1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 17.43% 0.968
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
3c1d8aa1-5a33-4ea4-8992-aadd6440af75 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283
Vendor Advisory