Active Exploitation of Ivanti Vulnerability CVE-2025-0282, Affecting Connect Secure and Policy Secure
An alert has been issued by Ivanti regarding a critical security vulnerability impacting Ivanti Connect Secure, Policy Secure, and ZTA Gateways. This vulnerability has been actively exploited since mid-December 2024.
The specific security issue is identified as CVE-2025-0282 (with a CVSS score of 9.0). It is a stack-based buffer overflow that impacts versions of Ivanti Connect Secure prior to 22.7R2.5 and Ivanti Policy Secure prior to 22.7R1.2
The specific security issue is identified as CVE-2025-0282 (with a CVSS score of 9.0). It is a stack-based buffer overflow that impacts versions of Ivanti Connect Secure prior to 22.7R2.5 and Ivanti Policy Secure prior to 22.7R1.2
