Ivanti Releases Security Update for Multiple Products
Two vulnerabilities affect Ivanti Connect Secure (ICS), Ivanti Policy Secure (IPS), and Ivanti Neurons for Zero-Trust Access (ZTA)
Summary
Two vulnerabilities affect Ivanti Connect Secure (ICS), Ivanti Policy Secure (IPS), and Ivanti Neurons for Zero-Trust Access (ZTA)
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Ivanti has released a security update to address two vulnerabilities affecting Connect Secure (ICS), Ivanti Policy Secure (IPS), and Ivanti Neurons for Zero-Trust Gateway. An attacker could exploit these vulnerabilities to cause a denial-of-service (DoS) condition and take control of an affected system.
Note: The Ivanti Neurons for Secure Access was affected by both vulnerabilities. Ivanti upgraded the hosted controller and completed the upgrade on October 09, 2022. There is no action to take regarding the Ivanti Neurons for Secure Access Controller.
Remediation advice
Affected organisations are encouraged to review Pulse security advisory SA45520 and apply the relevant update.
CVE Vulnerabilities
Last edited: 17 October 2022 4:36 pm