CVE-2025-0282

KEV
🔴 Łataj teraz

Przepełnienie bufora w Ivanti Connect Secure umożliwia zdalne wykonanie kodu przez nieautoryzowanego atakującego.

CVSS
9.0
EPSS
100.0%
Exploit
weaponized
Vendor
ivanti
Opis źródłowy (NVD)

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

buffer-overflow exploit rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.0
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)100.0%
Opublikowano (NVD)2025-01-08 23:15:09 UTC
Ostatnia modyfikacja (NVD)2026-08-04 05:16:32 UTC
Referencje