Knox CVE Database
/
CVE-2025-0282
Critical
9.0
Ransomware use

CVE-2025-0282: Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.

Added to the CISA KEV catalog:
January 8, 2025

Overview

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

Vulnerability details

Affected vendor
Ivanti
Affected product
Connect Secure, Policy Secure, and ZTA Gateways
Weakness type (CWE)
CWE-121

CVE-2025-0282 is a stack-based buffer overflow (CWE-121) affecting Ivanti Connect Secure, Policy Secure, and ZTA Gateways. In this weakness class, a program writes more data to a stack-allocated buffer than it can hold, overwriting adjacent memory including return addresses and control-flow data. In these VPN and network access gateway products, the overflow is reachable without authentication, meaning the vulnerable code path processes attacker-supplied input before any credential check occurs. This significantly widens the attack surface to any network-reachable instance.

An attacker who successfully exploits this vulnerability achieves unauthenticated remote code execution on the gateway. The CVSS vector indicates network-based delivery with no privileges or user interaction required, and a changed scope with high confidentiality, integrity, and availability impact. Because these gateways sit at the network perimeter and broker access to internal resources, a compromised device gives an attacker a persistent foothold for credential harvesting, lateral movement, and traffic interception. Active ransomware use confirms this exploitation path is operationally viable.

Severity and impact

9.0
Critical
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Known

Detection and monitoring

  • Monitor gateway management and VPN logs for unexpected process crashes, core dumps, or service restarts that may indicate failed or successful exploitation attempts.
  • Inspect outbound connections from gateway appliances to unfamiliar external hosts, as post-exploitation activity often involves command-and-control beaconing from the compromised device.
  • Review integrity of gateway configuration files and running processes using Ivanti's built-in Integrity Checker Tool, watching for unauthorized modifications consistent with post-exploitation persistence.
  • Alert on authentication log anomalies such as successful sessions with no corresponding credential validation, which may indicate attacker-controlled code bypassing normal auth flows.

Remediation

Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.
Federal (FCEB) remediation due date
January 15, 2025

Additional hardening

  • Restrict management interfaces and VPN endpoints to known IP ranges using perimeter firewall rules, reducing exposure to unauthenticated network attackers.
  • Place gateways in isolated network segments so a compromised appliance cannot directly reach internal systems without traversing additional inspection points.
  • Disable or limit non-essential services and listener ports on gateway appliances to reduce the attack surface available to unauthenticated remote input.
  • Conduct threat-hunting on internal hosts reachable through the gateway, prioritizing credential stores and identity infrastructure for signs of lateral movement.

Key dates

Published (NVD)
January 8, 2025
Added to CISA KEV
January 8, 2025
Remediation deadline
January 15, 2025
Last updated
August 4, 2026

References

Frequently asked questions

Does CVE-2025-0282 affect my FedRAMP authorization?

If Ivanti Connect Secure, Policy Secure, and ZTA Gateways runs inside your authorization boundary, yes. CVE-2025-0282 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of January 15, 2025. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2025-0282?

Knox doesn't patch your software for you — remediating Ivanti Connect Secure, Policy Secure, and ZTA Gateways is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.

What happens if CVE-2025-0282 isn't remediated by January 15, 2025?

It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

What this vulnerability means for your FedRAMP compliance

Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.

FedRAMP remediation deadlines for actively exploited vulnerabilities

FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.

How Knox reduces the burden of CVE vulnerabilities

Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.

How to limit your exposure through inherited controls and isolation

Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting