Vulnerabilidad crítica en Ivanti Connect Secure, Policy Secure y ZTA Gateways

Ivanti, a cybersecurity company, has recently disclosed two significant vulnerabilities affecting its products: Ivanti Connect Secure, Policy Secure, and ZTA Gateways. The more critical of the two issues is identified as CVE-2025-0282, which carries a CVSS (Common Vulnerability Scoring System) score of 9.0. This high severity rating indicates that an exploit could allow an unauthenticated attacker to execute arbitrary code remotely. The second vulnerability, CVE-2025-0283, has a CVSS score of 7.0 and can be exploited to escalate privileges for a local user.

CISA (Cybersecurity and Infrastructure Security Agency) and the NCSC-UK (National Cyber Security Centre – United Kingdom) have both reported active exploitation of CVE-2025-0282 in the wild. Ivanti has acknowledged that a limited number of its customers have been affected by these vulnerabilities, prompting the urgency to address the issues.

The affected versions of Ivanti’s products include:
– Ivanti Connect Secure, versions prior to 22.7R2.5
– Ivanti Policy Secure, versions prior to 22.7R1.2
– Ivanti Neurons for ZTA Gateways, versions prior to 22.7R2.3

Given the severity of these vulnerabilities, CERT-SE recommends that users immediately update their software in accordance with the guidelines provided by Ivanti to mitigate the risks associated with these security flaws.

For detailed guidance and remediation steps, Ivanti has released a security advisory, and additional information can be found through CISA and the NCSC-UK, emphasizing the necessity for prompt action to protect systems against potential exploitation.

Enlace de la fuente, haz clic para tener más información

Alertas y noticias de seguridad de la información

Contacta

Contacta con nosotros para obtener soluciones integrales en IT y seguridad de la información

Estamos encantados de responder cualquier pregunta que puedas tener, y ayudarte a determinar cuáles de nuestros servicios se adaptan mejor a tus necesidades.

Nuestros beneficios:
¿Qué sucede a continuación?
1

Programamos una llamada según tu conveniencia.

2

Realizamos una reunión de descubrimiento y consultoría.

3

Preparamos una propuesta.

Agenda una consulta gratuita