Sploitus

CVE-2024-22024

2 known exploits for CVE-2024-22024

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

Ivanti Connect Secure
= 9.1, 22.4, 22.5
Fix
Available
CVSS 3.1
8.3 HIGH
EPSS
94.7% (100th percentile)
Weakness
CWE-611
NVD status
Modified
Published
2024-02-13
CVE-2024-22024 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2024-22024

Proof-of-concept code and exploit modules indexed by Sploitus