{"id":3079,"date":"2025-04-05T10:05:43","date_gmt":"2025-04-05T10:05:43","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/04\/05\/cisa-adds-actively-exploits-ivanti-connect-secure-vulnerability-in-known-exploited-catalog\/"},"modified":"2025-04-05T10:05:43","modified_gmt":"2025-04-05T10:05:43","slug":"cisa-adds-actively-exploits-ivanti-connect-secure-vulnerability-in-known-exploited-catalog","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/04\/05\/cisa-adds-actively-exploits-ivanti-connect-secure-vulnerability-in-known-exploited-catalog\/","title":{"rendered":"CISA Adds Actively Exploits Ivanti Connect Secure Vulnerability in Known Exploited Catalog"},"content":{"rendered":"<p>    CISA Adds Actively Exploits Ivanti Connect Secure Vulnerability in Known Exploited Catalog<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-22457, a critical vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, to its Known Exploited Vulnerabilities (KEV) Catalog. <\/p>\n<p>This stack-based buffer overflow, actively exploited since mid-March 2025, allows remote unauthenticated attackers to achieve remote code execution (RCE), threatening organizations using these VPN and access solutions.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Vulnerability Details<\/strong><\/h2>\n<p>CVE-2025-22457 is a stack-based buffer overflow (CWE-121) with a CVSS score of 9.0, enabling attackers to execute arbitrary code without authentication. <\/p>\n<p>It impacts Ivanti Connect Secure (versions 22.7R2.5 and earlier), Pulse Connect Secure (versions 9.1R18.9 and prior, End-of-Support since December 31, 2024), Ivanti Policy Secure (versions 22.7R1.3 and prior), and ZTA Gateways (versions 22.8R2 and prior). <\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/ivanti-connect-secure-vulnerability-actively-exploited-in-the-wild\/\" target=\"_blank\" rel=\"noreferrer noopener\">Ivanti patched Connect Secure<\/a> in version 22.7R2.6 on February 11, 2025, with patches for Policy Secure and ZTA Gateways due on April 21 and April 19, respectively.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Active Exploitation<\/strong><\/h2>\n<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CISA added<\/a> CVE-2025-22457 to the KEV Catalog on April 4, 2025, following reports of exploitation. UNC5221, known for targeting edge devices, has <a href=\"https:\/\/cybersecuritynews.com\/chinese-hackers-actively-exploiting-ivanti-vpn-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">deployed malware like Trailblaz<\/a>e and Brushfire for persistent access and data theft. <\/p>\n<p>Exploitation began in mid-March, likely after UNC5221 reverse-engineered the February patch, underscoring the need for immediate updates.<\/p>\n<p>CISA\u2019s KEV Catalog, a vital resource for cybersecurity, lists vulnerabilities exploited in the wild to aid prioritization. Available in CSV, JSON, and print formats, it includes 1,314 entries. <\/p>\n<p>CVE-2025-22457\u2019s addition highlights its urgency, with a mitigation due date of April 11, 2025. CISA recommends using the catalog alongside BOD 22-01 guidance for cloud services to enhance vulnerability management.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Recommended Actions<\/strong><\/h2>\n<p>Start with threat hunting by using Ivanti\u2019s Integrity Checker Tool (ICT) to detect compromise, such as web server crashes, and perform threat hunts on connected systems.<\/p>\n<p>If no compromise is detected, conduct a factory reset with a clean image for cloud\/virtual systems, apply patches per Ivanti\u2019s advisory (Connect Secure 22.7R2.6; Policy Secure and ZTA Gateways patches due April 21 and 19), monitor authentication services, audit privileged accounts, and consider disconnecting vulnerable devices until patched.<\/p>\n<p>If a compromise is confirmed, isolate affected devices, take forensic images or coordinate with Ivanti, perform a factory reset with a clean image, revoke and reissue certificates, keys, and passwords (including admin and API credentials), reset domain account passwords twice, revoke Kerberos tickets, disable cloud-joined devices, apply patches, and report to CISA at Report@cisa.gov or (888) 282-0870, and to Ivanti.<\/p>\n<p>This is Ivanti\u2019s 15th KEV entry since 2024, reflecting ongoing security issues with its edge devices. UNC5221\u2019s involvement signals espionage risks from China-linked actors targeting infrastructure. An X post by<\/p>\n<p>CVE-2025-22457\u2019s inclusion in CISA\u2019s KEV Catalog emphasizes its immediate threat. With <a href=\"https:\/\/forums.ivanti.com\/s\/article\/April-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-22457?language=en_US\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">patches available <\/a>for Connect Secure and forthcoming for other products, organizations must act quickly to mitigate risks from sophisticated actors like UNC5221. <\/p>\n<p>CISA\u2019s guidance and Ivanti\u2019s updates offer a clear path to secure systems and prevent further exploitation in a challenging cyber landscape.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong><code><strong><code><strong>Find this News Interesting! Follow us on\u00a0<\/strong><a href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMOffpwsw1Oq_Aw?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Google News<\/strong><\/a><strong>,\u00a0<\/strong><a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>LinkedIn<\/strong><\/a><strong>, and\u00a0<\/strong><a href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>X<\/strong><\/a><strong>\u00a0to Get Instant Updates<\/strong><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisa-adds-actively-exploits-ivanti-connect-secure-vulnerability\/\">CISA Adds Actively Exploits Ivanti Connect Secure Vulnerability in Known Exploited Catalog<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Balaji N<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisa-adds-actively-exploits-ivanti-connect-secure-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Adds Actively Exploits Ivanti Connect Secure Vulnerability in Known Exploited Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-22457, a critical vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, to its Known Exploited Vulnerabilities (KEV) Catalog. This stack-based buffer overflow, actively exploited since mid-March 2025, allows remote unauthenticated attackers [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131],"tags":[130],"class_list":["post-3079","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3079"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3079"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3079\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3079"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3079"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3079"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}