Ivanti Security Updates – 14 December 2023

Ivanti has released security updates to fix multiple vulnerabilities across Ivanti Connect Secure and Ivanti Policy Secure.

The addressed vulnerabilities could allow the attacker to gain access, gain elevated privileges, or perform a denial of service attack on the affected systems.

Sample of the addressed vulnerabilities:

1. Ivanti Connect Secure Denial of Service Vulnerability (CVE-2023-39340):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service

2. Ivanti Connect Secure Remote Code Execution Vulnerability (CVE-2023-41719):

  • CVSS: 7.2
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2023-39340
  • CVE-2023-41719
  • CVE-2023-41720
  • CVE-2023-39339
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Ivanti Security Advisory

References