CVE-2024-22024

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
13/02/2024
Last modified:
09/05/2025

Description

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ivanti:connect_secure:9.1:r14.4:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:9.1:r17.2:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:9.1:r18.3:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:22.4:r2.2:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:22.5:r1.1:*:*:*:*:*:*
cpe:2.3:a:ivanti:connect_secure:22.5:r2.2:*:*:*:*:*:*
cpe:2.3:a:ivanti:policy_secure:22.5:r1.1:*:*:*:*:*:*
cpe:2.3:a:ivanti:zero_trust_access:22.6:r1.3:*:*:*:*:*:*