logo

Ivanti Rushes Patches for 4 New Flaws in Connect Secure and Policy Secure

ID: 0ebb66f0-0ee8-54ad-9dee-826faa47e71b

STIX ID: report--0ebb66f0-0ee8-54ad-9dee-826faa47e71b

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-04-04

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Ivanti released security updates for four vulnerabilities in Connect Secure and Policy Secure gateways: two heap overflow flaws (CVE-2024-21894, CVE-2024-22053) and a null pointer dereference (CVE-2024-22052) in the IPSec component enabling unauthenticated DoS and, in certain conditions, arbitrary code execution or memory disclosure, plus an XML entity expansion (CVE-2024-22023) in the SAML component that can cause temporary resource exhaustion. The company reports no known customer exploitation and is deploying patches while promising improvements to its security posture and vulnerability management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.