Ivanti Connect Secure, Policy Secure & ZTA Gateways customers, it's time to upgrade again as there's another two zero days already being exploited in the wild - CVE-2025-0282 and CVE-2025-0283
Unauth code execution.
ASLR prevents buffer overflow attacks, which CVE-2025-0282 is. However only about 5% of binaries in Ivanti's 'secure' Linux appliance have ASLR enabled - a two decade old security control. #yolosec https://infosec.exchange/@wdormann/113794200056523116
WatchTowr have a good look at the latest Ivanti Pulse Secure zero day.
Honestly? Don’t buy this product. It isn’t secure and they’re hiding problems. Swap to a better vendor.
@GossiTheDog any thoughts on “better vendor” for the same type of use cases? The other big names in the space seem as problematic. Sure wish we could flatten all the use cases for these boxes in to be able to be rid of them…