VDB
CVE-2025-0282
CVE-2025-0282
PUBLISHED
KEV
Connect Secure bietet TLS- und mobile VPN-Lösungen. Ivanti Policy Secure ist eine Network Access Control (NAC) Lösung.
EPSS 99.97% · 100.0th percentile
Risk Scores
EPSS Score
99.97%
100.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Ivanti Policy Secure =<22.7R1.2 | |
| Ivanti | Ivanti Connect Secure <22.7R2.5 |
Timeline
- Jan 8, 2025 CISA KEV Added
- Jan 8, 2025 VulnCheck KEV Exploitation
- Jan 8, 2025 PoC Published
- Jan 8, 2025 PoC Published
- Jan 8, 2025 PoC Published
- Jan 8, 2025 PoC Published
- Jan 8, 2025 PoC Published
- Jan 8, 2025 PoC Published
- Jan 8, 2025 PoC Published
- Jan 8, 2025 PoC Published
- Jan 8, 2025 PoC Published
- Jan 8, 2025 PoC Published
References
- Nuclei Template exploit
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0029.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0029 advisory
- https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283 advisory
- https://www.ivanti.com/blog/security-update-ivanti-connect-secure-policy-secure-and-neurons-for-zta-gateways advisory