Knox CVE Database
/
CVE-2025-0282
Critical
9.0
Ransomware use

CVE-2025-0282: Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.

Added to the CISA KEV catalog:
January 8, 2025

Overview

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

Vulnerability details

Affected vendor
Ivanti
Affected product
Connect Secure, Policy Secure, and ZTA Gateways
Weakness type (CWE)
CWE-121, CWE-787

CVE-2025-0282 is a stack-based buffer overflow (CWE-121, CWE-787) in the `/home/bin/web` binary on Ivanti Connect Secure, Policy Secure, and ZTA Gateway appliances. The binary handles IFT-TLS connections and copies the attacker-supplied `clientCapabilities` parameter into a fixed 256-byte stack buffer using `strncpy`, but passes the length of the input rather than the size of the destination buffer as the copy limit. Because stack canaries are absent, an oversized value overwrites adjacent stack variables and the saved return address without triggering a canary check.


An attacker sends an IFT-TLS request containing a `clientCapabilities` value exceeding 256 bytes to the internet-exposed appliance, requiring no authentication. Exploitation is version-specific, so attackers first probe the appliance using Host Checker Launcher and client installer URLs to identify the exact version. Successful exploitation yields remote code execution as root, enabling deployment of web shells, backdoors, and tunnelers, disabling of logging, and downstream network compromise. This vulnerability is actively exploited in ransomware campaigns and has been attributed to a suspected China-nexus espionage actor by Mandiant.

Severity and impact

9.0
Critical
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Known

Detection and monitoring

  • Run Ivanti's Integrity Checker Tool (ICT) against the appliance; a failed or modified-file result on a production device with no authorized change is a strong indicator of post-exploitation tampering.
  • Review appliance debug and application logs for gaps or deletions: post-exploitation activity includes use of `sed` to remove specific log entries, so missing time ranges in otherwise continuous logs indicate active log-tampering.
  • Monitor for HTTP requests to Host Checker Launcher and client installer URLs originating from VPS providers or Tor exit nodes, particularly in sequential version order, which Mandiant identifies as pre-exploitation reconnaissance.

Remediation

Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.
Federal (FCEB) remediation due date
January 15, 2025

Additional hardening

  • Restrict network access to the appliance management and IFT-TLS interfaces to known IP ranges; internet-wide exposure is the primary precondition for unauthenticated exploitation.
  • Configure external syslog forwarding to a separate, append-only log host so that post-exploitation `iptables` rules blocking syslog on ports 514 and 6514 are immediately detectable as a loss of log stream.
  • Disable or isolate Policy Secure and ZTA Gateway appliances that cannot be immediately patched, as all three product lines share the affected code path and are internet-reachable by design.
  • After patching, perform a factory reset before returning devices to service, consistent with CISA guidance, to remove any web shells or backdoors written during exploitation.

Key dates

Published (NVD)
January 8, 2025
Added to CISA KEV
January 8, 2025
Remediation deadline
January 15, 2025
Last updated
August 4, 2026

References

Frequently asked questions

Does CVE-2025-0282 affect my FedRAMP authorization?

If Ivanti Connect Secure, Policy Secure, and ZTA Gateways operate inside your authorization boundary, yes. CVE-2025-0282 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of January 15, 2025. An unpatched KEV within a FedRAMP boundary is an assessor finding: you either remediate it before review or formally document a mitigation. Neither your assessor nor your sponsoring agency will pass it without one of those two outcomes.

How does Knox help me handle CVE-2025-0282?

Remediating Ivanti Connect Secure, Policy Secure, and ZTA Gateways is your responsibility under the FedRAMP shared-responsibility model. Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work is yours to execute; maintaining a defensible compliance posture while you execute it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2025-0282 surfaces, exposure is identified through continuous monitoring rather than surfacing for the first time during an assessor's scheduled review, giving you time to act before it becomes a formal finding.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2025-0282 isn't remediated by January 15, 2025?

Miss the January 15, 2025 deadline and CVE-2025-0282 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization in good standing and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting