CNNVD-202508-1056 Information
CNNVD ID
CNNVD-202508-1056
Related CVE
- CNNVD Published: 2025-08-12
Description (Chinese)
Ivanti Connect Secure(ICS)等都是美国Ivanti公司的产品。Ivanti Connect Secure是一款安全远程网络连接工具。Ivanti Policy Secure(IPS)是一个网络访问控制 (NAC) 解决方案。Ivanti Neurons for Secure是一个安全云技术平台。 Ivanti多款产品存在安全漏洞,该漏洞源于XML外部实体引用,可能导致拒绝服务。以下产品和版本受到影响:Ivanti Connect Secure 22.7R2.8之前版本或22.8R2之前版本、Ivanti Policy Secure 22.7R1.5之前版本、Ivanti ZTA Gateway 22.8R2.3-723之前版本和Ivanti Neurons for Secure 22.8R1.4之前版本。
Description (English)
Ivanti Connect Security (ICS) and others are products of the American company Ivanti. Ivanti Contact Security is a secure remote network connection tool. Ivanti Policy Security is a web access control (NAC) solution. Ivanti Neurons for Security is a secure cloud technology platform. There is a safety loophole in Ivanti ’ s multiple products, which originates from an external XML entity and may lead to the denial of services. The following products and versions have been affected: previous version of Ivanti Contact 22.7R2.8 or previous version of 22.8R2, pre version of Ivanti Policy 22.7R1.5, pre version of Ivanti ZTA Gateway 22.8R2.3-723 and pre version of Ivanti Neurons for Security 22.8R1.4.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
Ivanti
Published
2025-08-12
Last Modified
2026-02-24