A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack or in certain conditions read contents from memory.
The product writes data past the end, or before the beginning, of the intended buffer.
The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.