CVE-2024-22053: High severity ivanti pulse connect secure vulnerability
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack or in certain conditions read contents from memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22053?
CVE-2024-22053 is considered a critical severity vulnerability due to its potential to cause a denial-of-service (DoS) and allow unauthorized memory access.
How do I fix CVE-2024-22053?
To fix CVE-2024-22053, you should update your Ivanti Connect Secure and Ivanti Policy Secure software to the latest patched versions provided by Ivanti.
What types of systems are affected by CVE-2024-22053?
CVE-2024-22053 affects various versions of Ivanti Connect Secure and Ivanti Policy Secure from 9.x and 22.x series.
What impact does CVE-2024-22053 have on my system?
The impact of CVE-2024-22053 includes potential service crashes and unauthorized access to sensitive memory contents.
Is my version vulnerable to CVE-2024-22053?
You are vulnerable to CVE-2024-22053 if you are running affected versions of Ivanti Connect Secure or Ivanti Policy Secure listed in the vulnerability report.