Skip to main content

Ivanti Releases Security Updates for Connect Secure and Policy Secure Gateways

Successful exploitation could lead to arbitrary code execution

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation could lead to arbitrary code execution


Threat details

Introduction

Ivanti has released security updates addressing four vulnerabilities in Connect Secure and Policy Secure Gateways. 

Ivanti Connect Secure and Policy Secure Gateways are SSL VPN solutions used for remote and mobile access to corporate resources.

Two of the vulnerabilities, CVE-2024-21894 and CVE-2024-22053, are heap overflow vulnerabilities with a CVSSv3 score of 8.2 and could allow an unauthenticated attacker to read contents from memory or perform arbitrary code execution. The other two vulnerabilities,  CVE-2024-22052 and CVE-2024-22023, could allow an authenticated attacker to cause a denial-of-service condition.


Remediation advice

Affected organisations are encouraged to review the Ivanti Security Advisory and apply any relevant security updates.



Last edited: 4 April 2024 1:12 pm