<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:ivanti:connect_secure:22.7:r2.1:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aivanticonnect_secure22.7r2.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 01:48:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aivanticonnect_secure22.7r2.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated RCE in Ivanti Connect Secure via CVE-2025-0282</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2025-0282/</link><pubDate>Thu, 03 Sep 2026 01:48:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2025-0282/</guid><description>A critical unauthenticated stack buffer overflow in Ivanti Connect Secure, Policy Secure, and Neurons for Zero-trust Access (version 22.7) allows remote attackers to execute arbitrary code and create unauthorized administrative accounts.</description><content:encoded><![CDATA[<p>CVE-2025-0282 is a critical stack buffer overflow vulnerability impacting multiple Ivanti products, including Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for Zero-trust Access, specifically version 22.7. The vulnerability exists within the unauthenticated interface, allowing remote attackers to trigger the overflow without prior access credentials. Proof-of-concept exploit code is publicly available, utilizing ROP chains to achieve code execution. Research indicates that successful exploitation leads to the creation of a local administrative account with root-level privileges (UID 0), granting the attacker full control over the appliance. Defenders should prioritize patching, as the presence of public exploit scripts significantly increases the risk of targeted exploitation against internet-facing appliances.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2025-0282 results in complete system compromise. By creating a persistent administrative account, an attacker can maintain long-term access, facilitate lateral movement within the network, and exfiltrate sensitive data managed by the Ivanti gateway. Given the criticality of these appliances as entry points for remote access, the risk to confidentiality, integrity, and availability is high.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately identify and patch all internet-facing Ivanti Connect Secure, Policy Secure, and Neurons for Zero-trust Access appliances running version 22.7.</li>
<li>Review administrative user account logs for the creation of unexpected accounts or modifications to existing accounts.</li>
<li>Restrict access to administrative and management interfaces to trusted internal IP ranges or VPN-only access to reduce the attack surface.</li>
<li>Monitor for anomalous outbound network traffic from Ivanti appliances, which may indicate post-exploitation activity or C2 communication.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>ivanti</category></item></channel></rss>