ZeroHour

CVE-2025-22457

KEV ransomwarelarge1

Unauthenticated Stack Buffer Overflow RCE in Ivanti Connect Secure

CISA: Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow (CWE-121) that can be triggered by a remote, unauthenticated attacker sending crafted input that overruns a fixed-size stack buffer on the affected gateway. Successful exploitation yields remote code execution on the appliance, giving an attacker control of an enterprise VPN or zero-trust access gateway and a foothold in the surrounding network. Any organization running the affected Ivanti gateway products is exposed, with impact concentrated among enterprises using these appliances for remote-access VPN and zero-trust network access. The vulnerability was added to CISA's KEV catalog on 2025-04-04 with known ransomware use, and its maximum EPSS score (100.0%, 100th percentile) signals near-certain exploitation pressure within 30 days. No public proof-of-concept is known, but confirmed in-the-wild exploitation makes this an actively abused, high-priority flaw.

What to do: Apply the mitigations required by CISA and update Connect Secure, Policy Secure, and ZTA Gateways to the patched releases designated in Ivanti's advisory, prioritizing internet-exposed VPN gateways. Given known ransomware use, review appliance and downstream logs for signs of compromise, and treat unpatched gateways as high risk given the 100th-percentile EPSS score.

Affected
Ivanti Connect Secure
Ivanti Policy Secure
Ivanti ZTA Gateways
Estimated exposure
largetens of thousands of deployed gateways, with on the order of 10k-100k internet-exposed appliances — Ivanti Connect Secure (formerly Pulse Secure) is a widely deployed enterprise VPN appliance, and public internet-exposure scans have historically shown tens of thousands of these gateways reachable online, so the estimate is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

CISA Known Exploited Vulnerability
Affected
Ivanti Connect Secure, Policy Secure, and ZTA Gateways
Required action
Apply mitigations as set forth in the CISA instructions linked below.
Due date
Ransomware use
Known
Vendors
ivanti
Products
connect secure, policy secure, zero trust access gateway
Weakness
CWE-121, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news