CVE-2024-22024
HIGH 8.3EPSS 94.7%
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
- CVSS v3.1
- 8.3 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L - CVSS v3.0
- 8.3 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L - EPSS
- 94.72% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- high
- Published
- 2024-02-13
- Updated
- 2025-05-09
Proof-of-concept exploits (2)
- 0dteam/CVE-2024-2202431★ · 2024-02-09
- tequilasunsh1ne/ivanti_CVE_2024_220240★ · 2024-10-08