Fiche vulnérabilité
CVE-2024-22024 : faille élevée ivanti connect secure (CVSS 8.3)
Description
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
En bref
- Sévérité
- Élevée (CVSS 8.3)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
- Exploitation active
- Non signalée par la CISA
- Publication
- 13 févr. 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- ivanti connect secure
- ivanti policy secure
- ivanti zero trust access gateway