« Volver al listado

Ivanti

Ivanti Neurons FOR Zero-trust Access: vulnerabilidades y CVE

Ivanti Neurons FOR Zero-trust Access tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses0
Críticas1
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-0282Crítica (9)100%⚠ Explotación activa8 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated…
CVE-2024-21893Alta (8.2)100%⚠ Explotación activa31 ene 2024
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-0283Alta (7)17%—8 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated…
CVE-2025-0282Crítica (9)100%⚠ Explotación activa8 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated…
CVE-2024-21893Alta (8.2)100%⚠ Explotación activa31 ene 2024
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted…
CVE-2022-35258Alta (7.5)2.7%—5 dic 2022
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions…
CVE-2022-35254Alta (7.5)2.7%—5 dic 2022
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1059 Command and Scripting Interpreter1
  3. T1059.003 Windows Command Shell1
  4. T1068 Exploitation for Privilege Escalation1
  5. T1090 Proxy1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Ivanti