Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-22024


An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.


Published

2024-02-13T04:15:07.943

Last Modified

2025-05-09T19:15:59.813

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.3 (HIGH)

Weaknesses
  • Type: Primary
    CWE-611
  • Type: Secondary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 22.4 Yes
Application ivanti connect_secure 22.5 Yes
Application ivanti connect_secure 22.5 Yes
Application ivanti policy_secure 22.5 Yes
Application ivanti zero_trust_access 22.6 Yes

References