An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.
References
Link | Resource |
---|---|
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA45520/?kA23Z000000GH5OSAW | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-12-05 14:15
Updated : 2022-12-08 11:20
NVD link : CVE-2022-35254
Mitre link : CVE-2022-35254
JSON object : View
CWE
CWE-400
Uncontrolled Resource Consumption
Products Affected
pulsesecure
- pulse_policy_secure
- pulse_connect_secure
ivanti
- neurons_for_zero-trust_access
- connect_secure
- policy_secure