← Back

CVE-2024-22024

Published: Feb 13, 2024Modified: Oct 31, 2025

JSON object

Loading...
8.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.7
Source: NVD

Description

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

Affected (8)

3 products
Connect Secure
Policy Secure
Zero Trust Access Gateway
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 22.4 r2.2
Version 22.5 r1.1
Version 22.5 r2.2
Version 9.1 r14.4
Version 9.1 r17.2
Version 9.1 r18.3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 22.5 r1.1
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 22.6 r1.3

Timeline

No history available yet.