Vulnerability Intelligence Report
CVE-2024-22024
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
Nuclei Template
CVSS Base Score
8.3
HIGH
Exploitability:3.9
Impact Score:3.8
EPSS Probability:94.72%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-611 ↗CWE-611 Improper Restriction of XML External Entity Reference
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Ivanti | ICS | 9.1R14.5 < 9.1R14.5 (affected), 9.1R17.3 < 9.1R17.3 (affected), 9.1R18.4 < 9.1R18.4 (affected), 22.1R6.1 < 22.1R6.1 (affected), 9.1R14.4 < 9.1R14.4 (unaffected), 9.1R15.2 < 9.1R15.2 (unaffected), 9.1R16.2 < 9.1R16.2 (unaffected), 9.1R17.2 < 9.1R17.2 (unaffected), 9.1R18.3 < 9.1R18.3 (unaffected), 22.1R6.1 < 22.1R6.1 (unaffected), 22.2R4.1 < 22.2R4.1 (affected), 22.3R1.1 < 22.3R1.1 (affected), 22.4R1.1 < 22.4R1.1 (affected), 22.5R1.2 < 22.5R1.2 (affected), 22.6R1.1 < 22.6R1.1 (affected), 22.4R2.3 < 22.4R2.3 (affected), 22.5R2.3 < 22.5R2.3 (affected), 22.6R2.2 < 22.6R2.2 (affected), 22.2R4.1 < 22.2R4.1 (unaffected), 22.3R1 < 22.3R1 (unaffected), 22.4R1.1 < 22.4R1.1 (unaffected), 22.5R1.1 < 22.5R1.1 (unaffected), 22.6R1.1 < 22.6R1.1 (unaffected), 22.4R2.2 < 22.4R2.2 (unaffected), 22.5R2.2 < 22.5R2.2 (unaffected), 22.6R2.2 < 22.6R2.2 (unaffected) |
| Ivant | ICS | 9.1R15.3 < 9.1R15.3 (affected) |
| Ivanti | IPS | 9.1R18.4 < 9.1R18.4 (affected), 9.1R17.3 < 9.1R17.3 (affected), 22.5R1.2 < 22.5R1.2 (affected), 9.1R18.2 < 9.1R18.2 (unaffected), 9.1R17.2 < 9.1R17.2 (unaffected), 22.5R1.1 < 22.5R1.1 (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | HackerOne · Bug Bounty Provider · USA |
| Reserved | 2024-01-04T01:04:06 |
| Published | 2024-02-13T04:07:04 |
| Last Updated | 2025-05-09T18:26:09 |
Community Chatter & Buzz