← Vulnerability feed

Vulnerability record · CVE-2024-22024 · published 13 February 2024

CVE-2024-22024: Ivanti Connect Secure SAML XXE allows unauthenticated resource access

Ivanti · Connect Secure

The SAML component of Ivanti Connect Secure, Policy Secure and ZTA gateways is vulnerable to XML external entity (XXE) injection (CWE-611). An attacker can craft XML that causes the server to resolve external entities, exposing restricted resources. Because the flaw sits in a pre-authentication SAML path, it is reachable without credentials and carries a high EPSS score, making it a realistic target for mass scanning.

8.3 CVSS 3.1 High EPSS 95% · top 0.1% CWE-611 · XML external entity (XXE)
8.3CVSS 3.1 base score
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable XXE with a very high EPSS score, though not in KEV and with only low-rated direct impact.

What it is

The SAML component of Ivanti Connect Secure, Policy Secure and ZTA gateways is vulnerable to XML external entity (XXE) injection (CWE-611). An attacker can craft XML that causes the server to resolve external entities, exposing restricted resources. Because the flaw sits in a pre-authentication SAML path, it is reachable without credentials and carries a high EPSS score, making it a realistic target for mass scanning.

Impact

An attacker gains read access to certain restricted resources on the appliance without authenticating. The CVSS vector rates confidentiality, integrity and availability impact as low but scope-changing, so the exposure extends beyond the vulnerable component.

Attack surface

Reached over the network via the SAML endpoint; the CVSS vector is AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The description confirms unauthenticated access to restricted resources.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.947 probability, 99.85th percentile), indicating elevated likelihood of exploitation. The only references are vendor advisories, so no public exploit details are confirmed in this record.

What to do

  • Apply the vendor patch from the Ivanti advisory for Connect Secure, Policy Secure and ZTA gateways.
  • If patching is delayed, restrict network access to the SAML endpoint to trusted sources only.
  • Disable or limit external entity resolution in the SAML/XML parser where configuration allows.
  • Monitor Ivanti advisories for updated fixed versions and any workaround guidance.
  • Audit appliances for signs of prior compromise before and after remediation.

Detection

  • Inspect SAML request bodies for DOCTYPE declarations or external entity references.
  • Alert on outbound connections from the appliance to unexpected hosts following SAML requests.
  • Review appliance logs for anomalous SAML endpoint access from untrusted source IPs.
  • Correlate high-volume scanning of the SAML path with subsequent file or resource access anomalies.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-22024 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-22024), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.