
⚠ HIGH PRIORITY — CISA KEV. CVE-2025-0288 is a stack buffer overflow in Ivanti Policy Secure and Connect Secure gateways. Unauthenticated remote attackers achieve RCE on VPN appliances — part of the 2025 Ivanti patch wave alongside CVE-2025-22457.
Affected Ivanti
- Policy Secure before 22.7R1.3
- Connect Secure builds listed in Ivanti advisory (patch alongside 22457)
- Internet-exposed VPN concentrators
Verify build
show version
show config sslPatching Method
- Apply latest Ivanti cumulative patch from security advisory (minimum fixed builds per product line).
- Run ICT/EAST scan before and after patching.
- Import patch via admin console; allow full reboot cycle.
- Disable internet VPN access until patch confirmed.
- Rotate all VPN user credentials and SAML secrets post-patch.
- Hunt for web shells and rogue admin accounts in appliance logs.
last -20
grep -i admin /var/log/messages 2>/dev/null | tail -30Workaround
- Block VPN portal at perimeter firewall immediately
- Restrict to IP allowlist if VPN must remain partially available