CVE-2024-22024

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
hackeroneCNA
8.3 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
ivanticonnect_secure
9.1:r14.4
ivanticonnect_secure
9.1:r17.2
ivanticonnect_secure
9.1:r18.3
ivanticonnect_secure
22.4:r2.2
ivanticonnect_secure
22.5:r1.1
ivanticonnect_secure
22.5:r2.2
ivantipolicy_secure
22.5:r1.1
ivantizero_trust_access
22.6:r1.3
𝑥
= Vulnerable software versions