CVE-2024-22024
high · 8.3A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
8.3
CVSS
94.7%
EPSS (exploit prob.)
100th
EPSS percentile
2024-02-13
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Weaknesses
CWE-611
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ivanti | connect_secure | 9.1 |
| ivanti | connect_secure | 9.1 |
| ivanti | connect_secure | 9.1 |
| ivanti | connect_secure | 22.4 |
| ivanti | connect_secure | 22.5 |
| ivanti | connect_secure | 22.5 |
| ivanti | policy_secure | 22.5 |
| ivanti | zero_trust_access_gateway | 22.6 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-22024