CVE-2024-22024
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 8.3epss 95%
from disclosure to weapon0 days
Published on NVDFeb 13
1st PoCFeb 9
VulnCheckFeb 6
exploitation probability
95%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
In short
A flaw in the SAML component allows attackers to read restricted files and resources on Ivanti Connect Secure, Policy Secure, and ZTA gateways without needing to log in. This happens because the system doesn't properly validate XML data, letting attackers inject external entity references.
Technical detail
An XXE (XML External Entity) vulnerability in the SAML processing logic of Ivanti Connect Secure and Policy Secure (versions 9.x, 22.x) and ZTA gateways permits unauthenticated attackers to access restricted resources. The vulnerability stems from insufficient validation of XML input, enabling entity expansion attacks to bypass access controls and retrieve sensitive data.
Summary generated and translated by AI from the official description.
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
public PoCs found — 1
vulncheckvulncheck.com/xdb/c4cadcd1e8e1unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.