Ivanti Connect Secure XML External Entity Vulnerability

CVE-2024-22024
8.3HIGH

Key Information

Vendor
Ivanti
Status
ICS
IPS
Vendor
CVE Published:
13 February 2024

Badges

🔥 No. 1 Trending😄 Trended👾 Exploit Exists🔴 Public PoC📰 News Worthy

Summary

The vulnerability CVE-2024-22024 affects the SAML component of Ivanti Connect Secure, Policy Secure, and ZTA gateways and allows an attacker to bypass authentication and access restricted resources. It has been found to be susceptible to exploitation, but there are no known instances of exploitation by ransomware groups. The suggested course of action is to upgrade Ivanti products to the fixed versions provided by the vendor in order to mitigate the risk of exploitation.

Affected Version(s)

ICS < 9.1R14.5

ICS < 9.1R17.3

ICS < 9.1R18.4

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 🔥

    Vulnerability reached the number 1 worldwide trending spot.

  • Vulnerability started trending.

  • Vulnerability published.

  • 👾

    Exploit exists.

  • First article discovered by Beeping Computers

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database1 Proof of Concept(s)13 News Article(s)
.