QID 150799
Date Published: 2024-02-12
QID 150799: Ivanti Connect Secure (ICS) XML External Entity (XXE) Vulnerability (CVE-2024-22024)
Ivanti Connect Secure (ICS) formerly known as Pulse Connect Secure, is a Remote Access VPN solution developed by Ivanti.
An XML external entity or XXE vulnerability exists in the SAML component which allows an attacker to access certain restricted resources without authentication.
Affected Versions:
Ivanti Connect Secure version 9.1R14.4
Ivanti Connect Secure version 9.1R17.2
Ivanti Connect Secure version 9.1R18.3
Ivanti Connect Secure version 22.4R2.2
Ivanti Connect Secure version 22.5R1.1
Ivanti Connect Secure version 22.5R2.2
QID Detection Logic:
This QID sends HTTP GET request to "dana-na/nc/nc_gina_ver.txt" endpoint and checks for vulnerable version of Ivanti Connect Secure (ICS).
NOTE:This QID does not check for Ivanti Policy Secure or ZTA gateway version.
Successful exploitation of this vulnerability could allow an attacker to access certain restricted resources without authentication.
CVEs related to QID 150799
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Ivanti 000090576 |
|