7.5
CVE-2022-35254
- EPSS 2.52%
- Veröffentlicht 05.12.2022 22:15:10
- Zuletzt bearbeitet 24.04.2025 15:15:47
- Erkennungen
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Connect Secure Version < 9.1
Ivanti ≫ Connect Secure Version 9.1 Update -
Ivanti ≫ Connect Secure Version 9.1 Update r1
Ivanti ≫ Connect Secure Version 9.1 Update r1.0
Ivanti ≫ Connect Secure Version 9.1 Update r10.0
Ivanti ≫ Connect Secure Version 9.1 Update r10.2
Ivanti ≫ Connect Secure Version 9.1 Update r11.0
Ivanti ≫ Connect Secure Version 9.1 Update r11.1
Ivanti ≫ Connect Secure Version 9.1 Update r11.3
Ivanti ≫ Connect Secure Version 9.1 Update r11.4
Ivanti ≫ Connect Secure Version 9.1 Update r11.5
Ivanti ≫ Connect Secure Version 9.1 Update r12
Ivanti ≫ Connect Secure Version 9.1 Update r12.1
Ivanti ≫ Connect Secure Version 9.1 Update r12.2
Ivanti ≫ Connect Secure Version 9.1 Update r13
Ivanti ≫ Connect Secure Version 9.1 Update r13.1
Ivanti ≫ Connect Secure Version 9.1 Update r14
Ivanti ≫ Connect Secure Version 9.1 Update r15
Ivanti ≫ Connect Secure Version 9.1 Update r16
Ivanti ≫ Connect Secure Version 9.1 Update r16.1
Ivanti ≫ Connect Secure Version 9.1 Update r2
Ivanti ≫ Connect Secure Version 9.1 Update r2.0
Ivanti ≫ Connect Secure Version 9.1 Update r3
Ivanti ≫ Connect Secure Version 9.1 Update r3.0
Ivanti ≫ Connect Secure Version 9.1 Update r4
Ivanti ≫ Connect Secure Version 9.1 Update r4.0
Ivanti ≫ Connect Secure Version 9.1 Update r4.1
Ivanti ≫ Connect Secure Version 9.1 Update r4.2
Ivanti ≫ Connect Secure Version 9.1 Update r4.3
Ivanti ≫ Connect Secure Version 9.1 Update r5
Ivanti ≫ Connect Secure Version 9.1 Update r5.0
Ivanti ≫ Connect Secure Version 9.1 Update r6
Ivanti ≫ Connect Secure Version 9.1 Update r6.0
Ivanti ≫ Connect Secure Version 9.1 Update r7
Ivanti ≫ Connect Secure Version 9.1 Update r7.0
Ivanti ≫ Connect Secure Version 9.1 Update r8
Ivanti ≫ Connect Secure Version 9.1 Update r8.0
Ivanti ≫ Connect Secure Version 9.1 Update r8.1
Ivanti ≫ Connect Secure Version 9.1 Update r8.2
Ivanti ≫ Connect Secure Version 9.1 Update r8.4
Ivanti ≫ Connect Secure Version 9.1 Update r9
Ivanti ≫ Connect Secure Version 9.1 Update r9.0
Ivanti ≫ Connect Secure Version 9.1 Update r9.1
Ivanti ≫ Connect Secure Version 9.1 Update r9.2
Ivanti ≫ Connect Secure Version 21.9 Update r1
Ivanti ≫ Connect Secure Version 21.12 Update r1
Ivanti ≫ Connect Secure Version 22.1 Update r1
Ivanti ≫ Connect Secure Version 22.2 Update -
Ivanti ≫ Connect Secure Version 22.2 Update r1
Ivanti ≫ Neurons For Zero-trust Access Version 22.2 Update r1
Ivanti ≫ Policy Secure Version < 9.1
Ivanti ≫ Policy Secure Version 9.1 Update -
Ivanti ≫ Policy Secure Version 9.1 Update r1
Ivanti ≫ Policy Secure Version 9.1 Update r10
Ivanti ≫ Policy Secure Version 9.1 Update r11
Ivanti ≫ Policy Secure Version 9.1 Update r12
Ivanti ≫ Policy Secure Version 9.1 Update r13
Ivanti ≫ Policy Secure Version 9.1 Update r13.1
Ivanti ≫ Policy Secure Version 9.1 Update r14
Ivanti ≫ Policy Secure Version 9.1 Update r15
Ivanti ≫ Policy Secure Version 9.1 Update r16
Ivanti ≫ Policy Secure Version 9.1 Update r2
Ivanti ≫ Policy Secure Version 9.1 Update r3
Ivanti ≫ Policy Secure Version 9.1 Update r3.1
Ivanti ≫ Policy Secure Version 9.1 Update r4
Ivanti ≫ Policy Secure Version 9.1 Update r4.1
Ivanti ≫ Policy Secure Version 9.1 Update r4.2
Ivanti ≫ Policy Secure Version 9.1 Update r5
Ivanti ≫ Policy Secure Version 9.1 Update r6
Ivanti ≫ Policy Secure Version 9.1 Update r7
Ivanti ≫ Policy Secure Version 9.1 Update r8
Ivanti ≫ Policy Secure Version 9.1 Update r8.1
Ivanti ≫ Policy Secure Version 9.1 Update r8.2
Ivanti ≫ Policy Secure Version 9.1 Update r9
Ivanti ≫ Policy Secure Version 22.1 Update r1
Ivanti ≫ Policy Secure Version 22.2 Update r1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.52% | 0.827 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA45520/?kA23Z000000GH5OSAW