Unauthenticated code execution via clientCapabilities overflow
Published Jan 8, 2025 · Updated Aug 4, 2026
Stack-based buffer overflow in Ivanti Connect Secure and related gateways allows remote attackers to execute code through IF-T TLS requests. The /home/bin/web IF-T handler passes the attacker-controlled clientCapabilities length to strncpy when copying into a 256-byte stack buffer, allowing the value to overwrite adjacent variables and control flow. No authentication or user interaction is required; Connect Secure before 22.7R2.5, Policy Secure 22.7R1 through 22.7R1.2, and Neurons for ZTA gateways 22.7R2 through 22.7R2.3 are affected.
Summary
What happened
Stack-based buffer overflow in Ivanti Connect Secure and related gateways allows remote attackers to execute code through IF-T TLS requests. The /home/bin/web IF-T handler passes the attacker-controlled clientCapabilities length to strncpy when copying into a 256-byte stack buffer, allowing the value to overwrite adjacent variables and control flow. No authentication or user interaction is required; Connect Secure before 22.7R2.5, Policy Secure 22.7R1 through 22.7R1.2, and Neurons for ZTA gateways 22.7R2 through 22.7R2.3 are affected.
The record
- CVE
- CVE-2025-0282
- Published
- Jan 8, 2025
- Updated
- Aug 4, 2026
- Vendor
- Ivanti
- Product
- Connect Secure
- Classifications
- CWE-121, T1190
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jan 8, 2025Exploitation reportedCISA Known Exploited Vulnerabilities entry
- Jan 8, 2025CVE publishedPublication date reported by the CVE source.
- Aug 4, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=22.7R2 <=22.7R2.4
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Rapid7 CVE-2025-0282 proof of conceptfunctional · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Reported exploitation
- RESURGE deployment after Connect Secure exploitationexploit chain
- CISA Known Exploited Vulnerabilities entryknown exploited catalog
- CISA ransomware-campaign associationransomware
- Limited Connect Secure exploitation reported by Ivantireported exploitation
- UNC5221 zero-day exploitation campaignthreat actor
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo