CVE-2024-22024 is an XML External Entity (XXE) vulnerability within the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x), and ZTA gateways. This critical flaw allows an unauthenticated attacker to access restricted resources. With a CVSS score of 8.3 (HIGH) and an EPSS score of 0.94249, it presents a significant risk due to its network-based attack vector, low attack complexity, and potential for partial confidentiality, integrity, and availability impact. While not currently listed in CISA's KEV catalog, its high community discussion and media coverage, along with the existence of Nuclei templates, indicate substantial interest and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.1CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.1:r14.4:*:*:*:*:*:* | ||
9.1CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.1:r17.2:*:*:*:*:*:* | ||
9.1CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.1:r18.3:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:22.4:r2.2:*:*:*:*:*:* | ||
22.5CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:22.5:r1.1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.