Alerts: Ivanti Releases Security Updates for Connect Secure, Policy Secure, and ZTA Gateways

Source URL: https://www.cisa.gov/news-events/alerts/2025/01/08/ivanti-releases-security-updates-connect-secure-policy-secure-and-zta-gateways
Source: Alerts
Title: Ivanti Releases Security Updates for Connect Secure, Policy Secure, and ZTA Gateways

Feedly Summary: Ivanti released security updates to address vulnerabilities (CVE-2025-0282, CVE-2025-0283) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways. A cyber threat actor could exploit CVE-2025-0282 to take control of an affected system.CISA has added CVE-2025-0282 to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
CISA urges organizations to hunt for any malicious activity, report any positive findings to CISA, and review the following for more information:

Security Advisory Ivanti Connect Secure, Policy Secure & ZTA Gateways (CVE-2025-0282, CVE-2025-0283)

For all instances of Ivanti Connect Secure, Policy Secure, and ZTA Gateways, see the following steps for general hunting guidance:

Conduct threat hunting actions:  

Run the In-Build Integrity Checker Tool (ICT). Instructions can be found here. 
Conduct threat hunt actions on any systems connected to—or recently connected to—the affected Ivanti device.  

If threat hunting actions determine no compromise: 

Factory reset the device and apply the patch described in Security Advisory Ivanti Connect Secure, Policy Secure & ZTA Gateways (CVE-2025-0282, CVE-2025-0283). 
Monitor the authentication or identity management services that could be exposed. 
Continue to audit privilege level access accounts. 

If threat hunting actions determine compromise: 

Report to CISA and Ivanti immediately to start forensic investigation and incident response activities.  
Disconnect instances of affected Ivanti Connect Secure products.  
Isolate the systems from any enterprise resources to the greatest degree possible. 
Revoke and reissue any connected or exposed certificates, keys, and passwords, to include the following: 

Reset the admin enable password. 
Reset stored application programming interface (API) keys. 
Reset the password of any local user defined on the gateway, including service accounts used for auth server configuration(s).  

If domain accounts associated with the affected products have been compromised: 

Reset passwords twice for on premise accounts, revoke Kerberos tickets, and then revoke tokens for cloud accounts in hybrid deployments. 
For cloud joined/registered devices, disable devices in the cloud to revoke the device tokens.

After investigation, fully patch and restore system to service.

Organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at Report@cisa.gov or (888) 282-0870. When available, please include the following information regarding the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact.

AI Summary and Description: Yes

Summary: The text highlights significant security updates from Ivanti addressing vulnerabilities in their products, particularly Ivanti Connect Secure, Policy Secure, and ZTA Gateways. It emphasizes the risk posed by exploitation of these vulnerabilities, urges organizations to engage in thorough threat hunting, and outlines necessary steps if a compromise is suspected, making it highly relevant for professionals in information security and infrastructure security.

Detailed Description: The provided text serves as a critical advisory regarding newly identified vulnerabilities (CVE-2025-0282 and CVE-2025-0283) impacting multiple Ivanti software products. These vulnerabilities could potentially allow cyber threat actors to take control of affected systems, prompting urgent action from organizations that use these products.

– **Key Vulnerabilities Identified**:
– **CVE-2025-0282**: Actively exploited vulnerability that could lead to unauthorized control of systems.
– **CVE-2025-0283**: Another vulnerability requiring attention, though less emphasis is placed on its specific risks.

– **CISA Involvement**:
– The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-0282 to its Known Exploited Vulnerabilities Catalog.
– Organizations are strongly urged to monitor for malicious activity and engage in threat hunting.

– **Recommended Actions for Organizations**:
– **Conduct Threat Hunting**:
– Utilize the In-Build Integrity Checker Tool (ICT) to assess system integrity.
– Investigate systems connected to affected Ivanti devices.

– **If No Compromise Detected**:
– Conduct a factory reset and apply relevant security patches.
– Monitor authentication and identity management systems.
– Audit privileged account access levels regularly.

– **If Compromise Detected**:
– Immediately report to CISA and Ivanti for forensic investigation and incident response.
– Disconnect affected devices and isolate from enterprise resources.
– Revoke and reissue compromised credentials, including resetting passwords on admin accounts and API keys.

– **Specific Actions for Domain Account Compromise**:
– Perform a double password reset for on-premise accounts, manage Kerberos tickets, and handle token revocation for hybrid cloud accounts.
– Disable compromised cloud-registered devices to secure their tokens.

The advisory concludes with information on how organizations can report incidents to CISA, indicating a structured approach to incident detection and response. The meticulous guidance provided not only enhances security protocols but also underscores the urgency for compliance and vigilance in managing cybersecurity threats.

This text carries substantial implications for professionals in the fields of security and compliance as it emphasizes proactive measures and strong incident response strategies in light of significant vulnerabilities in widely used infrastructure software.