High severity8.3NVD Advisory· Published Feb 13, 2024· Updated Jun 17, 2026
CVE-2024-22024
CVE-2024-22024
Description
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
Affected products
13cpe:2.3:a:ivanti:connect_secure:22.4:r2.2:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:ivanti:connect_secure:22.4:r2.2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.5:r1.1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:22.5:r2.2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r14.4:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r17.2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:connect_secure:9.1:r18.3:*:*:*:*:*:*
- (no CPE)range: 9.x, 22.x
cpe:2.3:a:ivanti:policy_secure:22.5:r1.1:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ivanti:policy_secure:22.5:r1.1:*:*:*:*:*:*
- (no CPE)range: 9.x, 22.x
- cpe:2.3:a:ivanti:zero_trust_access_gateway:22.6:r1.3:*:*:*:*:*:*
- Ivant/ICSv5Range: 9.1R15.3
- Ivanti/IPSv5Range: 9.1R18.4
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.