VYPR
High severity8.3NVD Advisory· Published Feb 13, 2024· Updated Jun 17, 2026

CVE-2024-22024

CVE-2024-22024

Description

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

Affected products

13
  • cpe:2.3:a:ivanti:connect_secure:22.4:r2.2:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:ivanti:connect_secure:22.4:r2.2:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:22.5:r1.1:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:22.5:r2.2:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:9.1:r14.4:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:9.1:r17.2:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:connect_secure:9.1:r18.3:*:*:*:*:*:*
    • (no CPE)range: 9.x, 22.x
  • cpe:2.3:a:ivanti:policy_secure:22.5:r1.1:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ivanti:policy_secure:22.5:r1.1:*:*:*:*:*:*
    • (no CPE)range: 9.x, 22.x
  • cpe:2.3:a:ivanti:zero_trust_access_gateway:22.6:r1.3:*:*:*:*:*:*
  • Ivant/ICSv5
    Range: 9.1R15.3
  • Ivanti/ICScpe-rescue
    Range: 9.1R14.5
  • Ivanti/IPSv5
    Range: 9.1R18.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.