60
CVE-2024-22024
—CVSS 3.1
8.3 high
EPSS
95%p100
Published
()
Modified
Description
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
- Vendors
- ivanti
- Products
- connect secure, policy secure, zero trust access gateway
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L