First published: Sat Dec 16 2023(Updated: )
A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific request which may lead to Denial of Service (DoS) of the appliance.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Connect Secure | =22.1-r1 | |
Ivanti Connect Secure | =22.1-r6 | |
Ivanti Connect Secure | =22.2 | |
Ivanti Connect Secure | =22.2-r1 | |
Ivanti Connect Secure | =22.3-r1 | |
Ivanti Connect Secure | =22.4-r1 | |
Ivanti Connect Secure | =22.4-r2.1 | |
Ivanti Connect Secure | =22.5-r2.1 | |
Ivanti Connect Secure | =9.1-r1 | |
Ivanti Connect Secure | =9.1-r1.0 | |
Ivanti Connect Secure | =9.1-r10 | |
Ivanti Connect Secure | =9.1-r10.0 | |
Ivanti Connect Secure | =9.1-r10.2 | |
Ivanti Connect Secure | =9.1-r11 | |
Ivanti Connect Secure | =9.1-r11.0 | |
Ivanti Connect Secure | =9.1-r11.1 | |
Ivanti Connect Secure | =9.1-r11.3 | |
Ivanti Connect Secure | =9.1-r11.4 | |
Ivanti Connect Secure | =9.1-r11.5 | |
Ivanti Connect Secure | =9.1-r12 | |
Ivanti Connect Secure | =9.1-r12.1 | |
Ivanti Connect Secure | =9.1-r12.2 | |
Ivanti Connect Secure | =9.1-r13 | |
Ivanti Connect Secure | =9.1-r13.1 | |
Ivanti Connect Secure | =9.1-r14 | |
Ivanti Connect Secure | =9.1-r14.4 | |
Ivanti Connect Secure | =9.1-r15 | |
Ivanti Connect Secure | =9.1-r15.2 | |
Ivanti Connect Secure | =9.1-r16 | |
Ivanti Connect Secure | =9.1-r16.1 | |
Ivanti Connect Secure | =9.1-r17 | |
Ivanti Connect Secure | =9.1-r17.1 | |
Ivanti Connect Secure | =9.1-r17.2 | |
Ivanti Connect Secure | =9.1-r18 | |
Ivanti Connect Secure | =9.1-r18.1 | |
Ivanti Connect Secure | =9.1-r2 | |
Ivanti Connect Secure | =9.1-r2.0 | |
Ivanti Connect Secure | =9.1-r3 | |
Ivanti Connect Secure | =9.1-r3.0 | |
Ivanti Connect Secure | =9.1-r4 | |
Ivanti Connect Secure | =9.1-r4.0 | |
Ivanti Connect Secure | =9.1-r4.1 | |
Ivanti Connect Secure | =9.1-r4.2 | |
Ivanti Connect Secure | =9.1-r4.3 | |
Ivanti Connect Secure | =9.1-r5 | |
Ivanti Connect Secure | =9.1-r5.0 | |
Ivanti Connect Secure | =9.1-r6 | |
Ivanti Connect Secure | =9.1-r6.0 | |
Ivanti Connect Secure | =9.1-r7 | |
Ivanti Connect Secure | =9.1-r7.0 | |
Ivanti Connect Secure | =9.1-r8 | |
Ivanti Connect Secure | =9.1-r8.0 | |
Ivanti Connect Secure | =9.1-r8.1 | |
Ivanti Connect Secure | =9.1-r8.2 | |
Ivanti Connect Secure | =9.1-r8.4 | |
Ivanti Connect Secure | =9.1-r9 | |
Ivanti Connect Secure | =9.1-r9.0 | |
Ivanti Connect Secure | =9.1-r9.1 | |
Ivanti Connect Secure | =22.6 | |
Ivanti Connect Secure | =22.6-r1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-39340 is assessed as critical due to its potential to cause Denial of Service (DoS) on affected Ivanti Connect Secure appliances.
To fix CVE-2023-39340, upgrade to Ivanti Connect Secure version 22.6R2 or later.
CVE-2023-39340 affects all versions of Ivanti Connect Secure below 22.6R2.
CVE-2023-39340 can lead to Denial of Service (DoS), causing system unavailability.
While there are no current reports of active exploitation for CVE-2023-39340, it is recommended to apply patches to mitigate potential risks.