← Back to browse · API

CVE-2024-22024

Severity
HIGH
CVSS
8.3
EPSS
0.94721
Risk score
66.35
CISA KEV
No
PoC
No
Published
2024-02-13
Modified
2025-05-09
First seen
2026-08-07
Aliases
EUVD-2024-19630, GHSA-CMG9-P9GP-G7MR
Products
Ivanti:ICS, Ivanti:ICS 22.1R6.1 <22.1R6.1, Ivanti:ICS 22.2R4.1 <22.2R4.1, Ivanti:ICS 22.3R1.1 <22.3R1.1, Ivanti:ICS 22.4R1.1 <22.4R1.1, Ivanti:ICS 22.4R2.3 <22.4R2.3, Ivanti:ICS 22.5R1.2 <22.5R1.2, Ivanti:ICS 22.5R2.3 <22.5R2.3, Ivanti:ICS 22.6R1.1 <22.6R1.1, Ivanti:ICS 22.6R2.2 <22.6R2.2, Ivanti:ICS 9.1R14.5 <9.1R14.5, Ivanti:ICS 9.1R15.3 <9.1R15.3, Ivanti:ICS 9.1R17.3 <9.1R17.3, Ivanti:ICS 9.1R18.4 <9.1R18.4, Ivanti:IPS, Ivanti:IPS 22.5R1.2 <22.5R1.2, Ivanti:IPS 9.1R17.3 <9.1R17.3, Ivanti:IPS 9.1R18.4 <9.1R18.4
Sources
euvd EUVD-2024-19630

Description

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

References