漏洞描述 Ivanti Connect Secure、Ivanti Policy Secure和Ivanti Neurons for ZTA gateways是Ivanti公司提供的远程访问和安全连接解决方案,主要功能包含VPN、访问控制、流量加密等。其IF-T/TLS协议在认证前,存在栈缓冲区溢出漏洞,攻击者可以利用该漏洞实现未授权远程代码执行。该漏洞已被APT组织利用。
相关漏洞推荐 CVE-2025-22457: Ivanti Connect Secure - Stack-based Buffer Overflow POC 2025-08-01 | Ivanti Connect Secure Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Iva... CVE-2024-21887: Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) - Command Injection POC 2025-08-01 | Ivanti Connect Secure A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti ... CVE-2024-22024: Ivanti Connect Secure - XXE POC 2025-08-01 | Ivanti Connect Secure Ivanti Connect Secure is vulnerable to XXE (XML External Entity) injection. Wordpress Plugin Depicter /wp-admin/admin-ajax.php depicter-lead-list SQL 注入漏洞(CVE-2025-2011) 无POC 2025-09-19 | Wordpress WordPress插件Depicter的滑块和弹出窗口构建器在包括3.6.1版本在内的所有版本中,由于用户提供的参数缺乏足够的转义处理和现有SQL查询的预处理不足,存在通用的SQL注入漏洞。该漏洞可以... Wordpress Plugin Eventin /wp-admin/admin-ajax.php proxy_image 文件读取漏洞(CVE-2025-3419) 无POC 2025-09-19 | Wordpress Event Manager, Events Calendar, Tickets, Registrations – Eventin 是一个用于 WordPress 的插件。该漏洞存在于其 proxy_i...