# CVE-2022-35258

## Summary

- **CVE ID:** CVE-2022-35258
- **Severity:** UNKNOWN
- **CVSS Score:** 0.39
- **CWE:** CWE-128
- **Published:** Dec 5, 2022
- **Last Modified:** Mar 13, 2026

## Description

An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.

## Affected Products

- n/a — Ivanti Connect Secure (ICS), Ivanti Policy Secure (IPS), and Ivanti Neurons for Zero Trust Access Gateway (ICS Prior to 9.1R14.3,9.1R15.2,9.1R16.2 and 22.2R4, IPS Prior to 9.1R17 and 22.3R1, Ivanti Neurons for Zero Trust Access Gateway Prior to 22.3R1)

## References

- [CNA](https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA45520/?kA23Z000000GH5OSAW)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 9.64%
- **EPSS Percentile:** 92.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._