Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
CVE-2025-0282 is a stack-based buffer overflow (CWE-121, CWE-787) in the `/home/bin/web` binary on Ivanti Connect Secure, Policy Secure, and ZTA Gateway appliances. The binary handles IFT-TLS connections and copies the attacker-supplied `clientCapabilities` parameter into a fixed 256-byte stack buffer using `strncpy`, but passes the length of the input rather than the size of the destination buffer as the copy limit. Because stack canaries are absent, an oversized value overwrites adjacent stack variables and the saved return address without triggering a canary check.
An attacker sends an IFT-TLS request containing a `clientCapabilities` value exceeding 256 bytes to the internet-exposed appliance, requiring no authentication. Exploitation is version-specific, so attackers first probe the appliance using Host Checker Launcher and client installer URLs to identify the exact version. Successful exploitation yields remote code execution as root, enabling deployment of web shells, backdoors, and tunnelers, disabling of logging, and downstream network compromise. This vulnerability is actively exploited in ransomware campaigns and has been attributed to a suspected China-nexus espionage actor by Mandiant.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Ivanti Connect Secure, Policy Secure, and ZTA Gateways operate inside your authorization boundary, yes. CVE-2025-0282 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of January 15, 2025. An unpatched KEV within a FedRAMP boundary is an assessor finding: you either remediate it before review or formally document a mitigation. Neither your assessor nor your sponsoring agency will pass it without one of those two outcomes.
Remediating Ivanti Connect Secure, Policy Secure, and ZTA Gateways is your responsibility under the FedRAMP shared-responsibility model. Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work is yours to execute; maintaining a defensible compliance posture while you execute it is not something you manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2025-0282 surfaces, exposure is identified through continuous monitoring rather than surfacing for the first time during an assessor's scheduled review, giving you time to act before it becomes a formal finding.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
Miss the January 15, 2025 deadline and CVE-2025-0282 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization in good standing and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









