ZeroHour

CVE-2024-22024

CVSS 3.1
8.3 high
EPSS
95%p100
Published
()
Modified
Description

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

Vendors
ivanti
Products
connect secure, policy secure, zero trust access gateway
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

In the news