Ivanti Releases Security Updates for Connect Secure and Policy Secure Gateways
Successful exploitation could lead to arbitrary code execution
Summary
Successful exploitation could lead to arbitrary code execution
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Ivanti has released security updates addressing four vulnerabilities in Connect Secure and Policy Secure Gateways.
Ivanti Connect Secure and Policy Secure Gateways are SSL VPN solutions used for remote and mobile access to corporate resources.
Two of the vulnerabilities, CVE-2024-21894 and CVE-2024-22053, are heap overflow vulnerabilities with a CVSSv3 score of 8.2 and could allow an unauthenticated attacker to read contents from memory or perform arbitrary code execution. The other two vulnerabilities, CVE-2024-22052 and CVE-2024-22023, could allow an authenticated attacker to cause a denial-of-service condition.
Remediation advice
Affected organisations are encouraged to review the Ivanti Security Advisory and apply any relevant security updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 4 April 2024 1:12 pm