A critical vulnerability impacting Ivanti softwares Connect Secure, Neurons for Zero Trust Access and Policy Secure has been reported. It has been assigned the reference CVE-2025-0282 and a CVSS 3.1 score of 9.0. 

It should be noted that proof of concept of this CVE-2025-0282 vulnerability are publicly available.

 

Initial vector attack of the Ivanti vulnerability

The vulnerability allows an unauthenticated attacker to trigger a remote code execution.

 

Technical details of the Ivanti vulnerability

The 'web' exposed service performs an improper size check on a string received from a user, which can lead to a stack overflow and possible takeover of the service by an external attacker.

 

Attack modelling with MITRE ATT&CK

MITRE ATT&CK

  • T1190 (Exploit Public-Facing Application)

 

How to protect against the Ivanty vulnerability with Stormshield Network Security

Protection against CVE-2025-0282

Stormshield Network Security (SNS) firewalls detect and block exploitation of CVE-2025-0282 with the protocol inspection:

  • http:53: Protocole HTTP invalide

Confidence index for the protection offered by Stormshield

Confidence index for the absence of false positives

Recommandations regarding the Ivanti vulnerability

It is therefore strongly recommended to update your Ivanti softwares:

  1. Connect Secure : 22.7R2.5 or higher
  2. Neurons for Zero Trust Access : 22.8R2 or higher
  3. Policy Secure : 22.7R1.3 or higher

Share on

[juiz_sps buttons="facebook, twitter, linkedin, mail"]
Need more information about Stormshield protection? The Technical Support teams are at your disposal to help you. Contact them through the incident manager located in the MyStormshield private area. To access it, select the menu "Technical Support / Report an incident / Track an incident".
Stormshield's Cyber Threat Intelligence team has two primary missions: to study cyber threats to understand them and to continuously improve Stormshield product protections. All with the goal of contributing to the cybersecurity community's effort to address cyber threats.