CVE-2025-0282
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 9
- EPSS
- 100.0% 백분위 100.0% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2025.01.15
- 공개일
- 2025.01.09
CISA KEV에 등록된 실제 악용 확인 취약점
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
공급사 Ivanti
제품 Connect Secure, Policy Secure, and ZTA Gateways
영향 버전 22.7R2, 22.7R1, 22.7
수정 버전 공식 출처에서 확인 필요
Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.
조치 기한: 2025.01.15CVSS 벡터 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE CWE-121, CWE-787
KEV 등록일 2025.01.08
랜섬웨어 캠페인 사용 확인됨
CISA 비고 CISA Mitigation Instructions: https://www.cisa.gov/cisa-mitigation-instructions-CVE-2025-0282 Additional References: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283 ; https://nvd.nist.gov/vuln/detail/CVE-2025-0282
EPSS 데이터 기준일 2026.06.27