Ivanti VPN customers targeted via unrecognized RCE vulnerability (CVE-2025-22457)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-21887 +1 in the same advisory: …46805 | Command Injection RCE in Ivanti Connect Secure and Policy Secure Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available. Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories. | 9.1 group max | 100% | KEV ransomware PoC |
| largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher) | |
| CVE-2023-4966 | Info-Disclosure Buffer Overflow (CitrixBleed) in Citrix NetScaler ADC/Gateway Citrix NetScaler ADC and NetScaler Gateway appliances contain a buffer overflow (CWE-119) that leaks sensitive information from device memory when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. A remote attacker who can reach such a configuration can trigger the overflow and read memory contents, harvesting sensitive data such as session tokens (a technique that enables session hijacking which can bypass multi-factor authentication). Any organization running an affected NetScaler ADC or Gateway appliance in these configurations is exposed, with appliances deployed as VPN or access gateways being the primary concern. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2023-10-18 with known ransomware use and a 100% EPSS exploitation probability, although no public proof-of-concept is known at this time. Because tokens stolen from memory can remain valid even after patching, responders must terminate all active and persistent sessions as part of remediation. Do: Upgrade affected appliances to the patched builds cited in Citrix's advisory, then immediately kill all active and persistent ICA/AAA sessions per the vendor instructions, since patching alone does not invalidate session tokens attackers may have already stolen. If patching is not immediately possible, discontinue use of the affected Gateway/AAA configurations as CISA directs. Given known ransomware abuse, also hunt for signs of exploitation such as logins from unexpected sources, anomalous session reuse, or suspicious mailbox changes, and reset credentials for potentially exposed accounts. | 7.5 | 100% | KEV ransomware |
| masshundreds of thousands of internet-exposed NetScaler ADC/Gateway appliances (public internet scan counts), plus an unknown number of VPN-only or internal… | |
| CVE-2025-0282 | Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known. Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin. | 9.0 | 100% | KEV ransomware PoC ×3 |
| largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways) | |
| CVE-2025-22457 | Unauthenticated Stack Buffer Overflow RCE in Ivanti Connect Secure Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow (CWE-121) that can be triggered by a remote, unauthenticated attacker sending crafted input that overruns a fixed-size stack buffer on the affected gateway. Successful exploitation yields remote code execution on the appliance, giving an attacker control of an enterprise VPN or zero-trust access gateway and a foothold in the surrounding network. Any organization running the affected Ivanti gateway products is exposed, with impact concentrated among enterprises using these appliances for remote-access VPN and zero-trust network access. The vulnerability was added to CISA's KEV catalog on 2025-04-04 with known ransomware use, and its maximum EPSS score (100.0%, 100th percentile) signals near-certain exploitation pressure within 30 days. No public proof-of-concept is known, but confirmed in-the-wild exploitation makes this an actively abused, high-priority flaw. Do: Apply the mitigations required by CISA and update Connect Secure, Policy Secure, and ZTA Gateways to the patched releases designated in Ivanti's advisory, prioritizing internet-exposed VPN gateways. Given known ransomware use, review appliance and downstream logs for signs of compromise, and treat unpatched gateways as high risk given the 100th-percentile EPSS score. | 9.8 | 100% | KEV ransomware |
| largetens of thousands of deployed gateways, with on the order of 10k-100k internet-exposed appliances |
Full article797 words · extracted from helpnetsecurity.com · click to collapse
A suspected Chinese APT group has exploited CVE-2025-22457 – a buffer overflow bug that was previously thought not to be exploitable – to compromise appliances running Ivanti Connect Secure (ICS) 22.7R2.5 or earlier or Pulse Connect Secure 9.1x.

The vulnerability was patched by Ivanti in ICS 22.7R2.6, released on February 11, 2025. But, apparently, the threat actor studied the patch and “uncovered through a complicated process, [that] it was possible to exploit 22.7R2.5 and earlier to achieve remote code execution,” Mandiant (Google) incident responders have revealed.
“Mandiant and Ivanti have identified evidence of active exploitation in the wild against ICS 9.X (end of life) and 22.7R2.5 and earlier versions.”
CVE-2025-22457 exploited, old and new malware used
Temporarily labeled as UNC5221, the suspected China-nexus espionage actor is believed to be the same one who previously exploited several zero-day bugs in Ivanti’s solutions: CVE-2025-0282, CVE-2023-46805 and CVE-2024-21887. They have also been behind zero-day attacks hitting NetScaler ADC and NetScaler Gateway appliances via CVE-2023-4966, aka “CitrixBleed”.
“The earliest evidence of observed CVE-2025-22457 exploitation occurred in mid-March 2025,” Google’s researchers noted.
Once in, the attackers deployed two new malware families – the TRAILBLAZE in-memory only dropper and the BRUSHFIRE passive backdoor – as well as elements of the SPAWN malware ecosystem that was seen in previous UNC5221 attacks, including:
- SPAWNSLOTH – a log tampering utility
- SPAWNSNARE – a utility used to extract the uncompressed linux kernel image (vmlinux) into a file and encrypt it
- SPAWNWAVE – a tool combining the capabilities of the SPAWNCHIMERA and RESURGE malware families
- A modified version of Ivanti’s Integrity Checker Tool (ICT) to evade detection
“[Google Threat Intelligence Group (GTIG)] assesses that UNC5221 will continue pursuing zero-day exploitation of edge devices based on their consistent history of success and aggressive operational tempo. Additionally, (…) GTIG has observed UNC5221 leveraging an obfuscation network of compromised Cyberoam appliances, QNAP devices, and ASUS routers to mask their true source during intrusion operations,” Google’s experts added.
What to do?
“[CVE-2025-22457] is a buffer overflow with characters limited to periods and numbers, it was evaluated and determined not to be exploitable as remote code execution and didn’t meet the requirements of denial of service,” according to Ivanti.
It affects Ivanti Connect Secure versions 22.7R2.5 and earlier, Pulse Connect Secure 9.x (which reached end-of-support in December 2024), Ivanti Policy Secure and ZTA gateways.
The latter two solutions are somewhat protected and there’s no indication they have been targeted.
But a “limited” number of customers running vulnerable Ivanti Connect Secure and Pulse Connect Secure have been affected.
As noted before, CVE-2025-22457 was fixed in Ivanti Connect Secure 22.7R2.6 and users should upgrade to that or a later version. Since Pulse Connect Secure 9.x is no longer supported, Ivanti advises customers to get in touch so they can assist them in a migration to “a secure platform.”
Patches for the flaw in Ivanti Policy Secure and ZTA Gateways are being developed and will be released on April 21 and April 19, respectively.
Customers who are part of the pool of possible victims – i.e., those who are still running a vulnerable Ivanti Connect Secure and Pulse Connect Secure version – should check whether their devices have been compromised.
“Customers should monitor their external ICT and look for web server crashes. If your ICT result shows signs of compromise, you should perform a factory reset on the appliance and then put the appliance back into production using version 22.7R2.6,” the company advised.
“To supplement this, defenders should actively monitor for core dumps related to the web process, investigate ICT statedump files, and conduct anomaly detection of client TLS certificates presented to the appliance,” Google’s professionals have advised, and they have also released hashes of the malware used and YARA rules to detect some of it.
UPDATE (April 11, 2025, 06:20 a.m. ET):
“Network security devices and edge devices in particular are a focus of sophisticated and highly persistent threat actors, and Ivanti is committed to providing information to defenders to ensure they can take every possible step to secure their environments. To this end, in addition to providing an advisory directly to customers, Ivanti worked closely with its partner Mandiant to provide additional information regarding this recently addressed vulnerability,” Daniel Spicer, Ivanti CSO told Help Net Security.
“Importantly, this vulnerability was fixed in ICS 22.7R2.6, released February 11, 2025, and customers running supported versions on their appliances and in accordance with the guidance provided by Ivanti have a significantly reduced risk. Ivanti’s Integrity Checker Tool (ICT) has been successful in detecting potential compromise on a limited number of customers running ICS 9.X (end of life) and 22.7R2.5 and earlier versions.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/04/03/ivanti-vpn-customers-targeted-via-unrecognized-rce-vulnerability-cve-2025-22457/