S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 2, 2024

CVE-2024-22024 Scanner

Detects 'XXE' vulnerability in Ivanti Connect Secure products

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-22024
8.3
CVSShigh
Exploitable remotely over the internet · no authentication required.

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ICSby Ivanti
AFFECTED< 9.1R14.5SAFE ✓≥ 9.1R14.5
ICSby Ivant
AFFECTED< 9.1R15.3SAFE ✓≥ 9.1R15.3
IPSby Ivanti
AFFECTED< 9.1R18.4SAFE ✓≥ 9.1R18.4
Updated Aug 22, 2026View on NVD →
Detail

Ivanti Connect Secure is a remote access solution designed to provide secure connections for users to access corporate networks and resources remotely. It is commonly used by organizations to enable remote work capabilities while maintaining security standards. Ivanti Connect Secure ensures encrypted and authenticated connections between remote users and corporate networks, facilitating secure access to applications and data from anywhere, at any time.

The vulnerability detected in Ivanti Connect Secure is an XML External Entity (XXE) injection flaw. This vulnerability allows an attacker to inject malicious XML entities into XML documents processed by the application, potentially leading to unauthorized access to sensitive information or even remote code execution on the server.

The vulnerability resides in the '/dana-na/auth/saml-sso.cgi' endpoint of Ivanti Connect Secure, where it fails to properly validate and sanitize XML input. By crafting a specially crafted XML payload containing malicious entities, an attacker can trigger the XXE vulnerability, leading to unauthorized access to sensitive data or potential remote code execution on the server.

Exploiting this vulnerability can allow attackers to access sensitive information stored on the server or execute arbitrary code in the context of the application, potentially leading to complete compromise of the affected system. Attackers can leverage this vulnerability to steal sensitive data, launch further attacks against other systems, or disrupt the normal operation of the application.

By leveraging the security scanning capabilities of the S4E platform, you can identify critical vulnerabilities like XXE in Ivanti Connect Secure before they are exploited by malicious actors. Join our platform to proactively protect your organization's remote access infrastructure and ensure the security of your sensitive data and resources.

 

References

Solution Advice
  • Apply the latest security patches or updates provided by Ivanti to fix the XXE vulnerability.
  • Implement strict input validation and sanitization mechanisms to prevent malicious XML entities from being processed by the application.
  • Consider using a web application firewall (WAF) to detect and block malicious XML payloads attempting to exploit the XXE vulnerability.
  • Regularly monitor system logs and network traffic for signs of XXE attacks or unusual activity indicative of attempted exploitation.
  • Educate system administrators and developers about secure coding practices and the risks associated with XXE vulnerabilities to prevent similar security issues in the future.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.