216.73.217.22

CVE-2024-22024

· Published 13/02/2024 05:15 · Modified 27/05/2026 21:40 · Author: The MITRE Corporation

Labels: CVE-2024-22024

Essential information

Published
13/02/2024 05:15
Modified
27/05/2026 21:40
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
8.3 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/C:L/I:L/A:L

CVSS metrics

Description

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

NVD status

NVD
View on NVD