← All CVEs

CVE-2024-22024

high · 8.3

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

8.3
CVSS
94.7%
EPSS (exploit prob.)
100th
EPSS percentile
2024-02-13
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Weaknesses

CWE-611

Affected products

VendorProductAffected versions
ivanticonnect_secure9.1
ivanticonnect_secure9.1
ivanticonnect_secure9.1
ivanticonnect_secure22.4
ivanticonnect_secure22.5
ivanticonnect_secure22.5
ivantipolicy_secure22.5
ivantizero_trust_access_gateway22.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-22024