Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2025-0282

 

Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2025-0282

Published: January 8, 2025 / Updated: June 13, 2025


Vulnerability identifier: #VU102473
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-0282
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when handling untrusted input. A remote unauthenticated attacker can send specially crafted packets to the system, trigger a stack-based buffer overflow and execute arbitrary code on the target system.

Note, the vulnerability is being actively exploited in the wild against Ivanti Connect Secure instances.


Affected software

Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Neurons for ZTA gateways

How to mitigate CVE-2025-0282

Install updates from vendor's website.

Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 22.7R2.5
Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 22.7R1.3
Ivanti Neurons for ZTA gateways - update to 22.8R2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins