KEVIntel
8.3
CVSS
High

CVE-2024-22024

PUBLISHED

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA...

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
Ivanti, Ivant
Product
ICS, IPS
Published
Feb 13, 2024
EPSS

Description

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

nuclei_scanner edge

CVSS scores

CVSS v3.0 8.3 High

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Exploitation status

Exploited in the wild

Recorded 2025-04-28 00:00:00 UTC · Source

Proof of concept available

Recorded 2024-02-09 14:31:56 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Apr 28, 2025

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

0dteam/CVE-2024-22024

github · Created 2024-02-09 14:31:56 UTC · 30 stars

Check for CVE-2024-22024 vulnerability in Ivanti Connect Secure

Timeline

  • CVE ID Reserved

  • Proof of Concept Exploit Available

  • CVE Published to Public

  • Detected by Nuclei

  • Added to KEVIntel