A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack
The product dereferences a pointer that it expects to be valid but is NULL.
The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.