A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
🚨 This vulnerability is known to be exploited in the wild.
CVE ID: CVE-2025-0282
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.0
Vendor: Ivanti
Product: Connect Secure
EPSS Score: 15.33% (probability of being exploited)
EPSS Percentile: 95.9% (scored less or equal to compared to others)
EPSS Date: 2025-02-06 (when was this score calculated)