Ivanti Rushes Patches for 4 New Flaws in Connect Secure and Policy Secure
ID: 0ebb66f0-0ee8-54ad-9dee-826faa47e71b
STIX ID: report--0ebb66f0-0ee8-54ad-9dee-826faa47e71b
Feed Name: The Hacker News
Ivanti released security updates for four vulnerabilities in Connect Secure and Policy Secure gateways: two heap overflow flaws (CVE-2024-21894, CVE-2024-22053) and a null pointer dereference (CVE-2024-22052) in the IPSec component enabling unauthenticated DoS and, in certain conditions, arbitrary code execution or memory disclosure, plus an XML entity expansion (CVE-2024-22023) in the SAML component that can cause temporary resource exhaustion. The company reports no known customer exploitation and is deploying patches while promising improvements to its security posture and vulnerability management.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
