CVE-2023-39340: Ivanti Connect Secure

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific request which may lead to Denial of Service (DoS) of the appliance.

Affected products

  • Ivanti Connect Secure: version 22.1 only; version 22.2 only; version 22.3 only; version 22.4 only; version 22.5 only; version 9.1 only; …

Published 2023-12-16. Last modified 2026-06-17.