CISA warns of latest Ivanti firewall bug being exploited by suspected Chinese hackers
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-21887 +1 in the same advisory: …46805 | Command Injection RCE in Ivanti Connect Secure and Policy Secure Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available. Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories. | 9.1 group max | 100% | KEV ransomware PoC |
| largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher) | |
| CVE-2025-0282 | Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known. Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin. | 9.0 | 100% | KEV ransomware PoC ×3 |
| largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways) | |
| CVE-2025-22457 | Unauthenticated Stack Buffer Overflow RCE in Ivanti Connect Secure Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow (CWE-121) that can be triggered by a remote, unauthenticated attacker sending crafted input that overruns a fixed-size stack buffer on the affected gateway. Successful exploitation yields remote code execution on the appliance, giving an attacker control of an enterprise VPN or zero-trust access gateway and a foothold in the surrounding network. Any organization running the affected Ivanti gateway products is exposed, with impact concentrated among enterprises using these appliances for remote-access VPN and zero-trust network access. The vulnerability was added to CISA's KEV catalog on 2025-04-04 with known ransomware use, and its maximum EPSS score (100.0%, 100th percentile) signals near-certain exploitation pressure within 30 days. No public proof-of-concept is known, but confirmed in-the-wild exploitation makes this an actively abused, high-priority flaw. Do: Apply the mitigations required by CISA and update Connect Secure, Policy Secure, and ZTA Gateways to the patched releases designated in Ivanti's advisory, prioritizing internet-exposed VPN gateways. Given known ransomware use, review appliance and downstream logs for signs of compromise, and treat unpatched gateways as high risk given the 100th-percentile EPSS score. | 9.8 | 100% | KEV ransomware |
| largetens of thousands of deployed gateways, with on the order of 10k-100k internet-exposed appliances |
Full article604 words · extracted from therecord.media · click to collapse
Another vulnerability impacting firewall products from Ivanti is being exploited by alleged China-based hackers. An Ivanti advisory released on Thursday confirmed that a “limited number of customers” have been attacked through a bug impacting its Connect Secure, Policy Secure & ZTA Gateways tools — which are used by large organizations and government clients to keep malicious traffic out while allowing employees to have remote access to systems. On Friday, the Cybersecurity and Infrastructure Security Agency (CISA) also confirmed exploitation of the vulnerability, tracked as CVE-2025-22457. Mandiant and Google Threat Intelligence Group (GTIG) said they are attributing its exploitation and the subsequent deployment of a malware ecosystem known as Spawn to a suspected China-based espionage actor they track as UNC5221. Ivanti released a patch for the vulnerability on February 11 but noted that the bug also impacts certain devices that are no longer supported by the company as of the end of 2024. “We are aware of a limited number of customers whose Ivanti Connect Secure (22.7R2.5 and earlier) and End-of-Support Pulse Connect Secure 9.1x appliances have been exploited at the time of disclosure,” Ivanti said in its advisory. “The risk from this vulnerability is significantly reduced for customers running appliances on supported versions. Ivanti cannot provide guidance to customers to stay on an unsupported version. Customers' only option is to migrate to a secure platform to ensure their security.” Ivanti said customers can tell if they have been compromised by using an integrity checker tool, and if they are impacted they should perform a factory reset on the appliance. The company noted that it initially believed the bug was not exploitable but learned alongside cybersecurity experts that it can be exploited “through sophisticated means.” Ivanti repeatedly warned that customers who are continuing to use end-of-life devices “do so at their own risk” and said the company “will not provide any troubleshooting or code change for products that are no longer supported.” Ivanti directed customers to Mandiant’s blog for more information about exploitation. Mandiant said the earliest evidence of exploitation appeared in mid-March. They observed the hackers deploy two new malware families, including a backdoor called Brushfire. The hackers also deployed the Spawn ecosystem of malware, which CISA spotlighted in an advisory last week. Google and Mandiant said the same actor previously exploited CVE-2025-0282 — a bug affecting the same Ivanti tools which emerged in January — as well as past Ivanti vulnerabilities like CVE-2023-46805 and CVE-2024-21887. The same hackers, allegedly based in China, have been exploiting edge devices like those produced by Ivanti since 2023. “UNC5221 has targeted a wide range of countries and verticals during their operations, and has leveraged an extensive set of tooling, spanning passive backdoors to trojanized legitimate components on various edge appliances,” Mandiant said. The hackers are also using a network of “compromised Cyberoam appliances, QNAP devices, and ASUS routers to mask their true source during intrusion operations.” Experts at cybersecurity firm watchTowr examined the vulnerability and the patch and told Recorded Future News the bug was further proof that active exploitation of vulnerabilities in mission-critical appliances continues to be a constant concern. “It is vital organizations do their own analysis, and that the industry continues to review vulnerabilities and their exploitability and impact independently when making risk decisions,” said watchTowr CEO Benjamin Harris. Brushfire
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-ivanti-firewall-bug-exploitation