QID 731145
Date Published: 2024-02-09
QID 731145: Ivanti Connect Secure Extensible Markup Language (XML) External Entity (XXE) Vulnerability
Ivanti Connect Secure provides a seamless, cost-effective, SSL VPN solution for remote and mobile users from any web-enabled device to corporate resources
CVE-2024-22024: An XML external entity or XXE vulnerability in the SAML component allows an attacker to access certain restricted resources without authentication.
Affected Versions:
Ivanti Connect Secure version 9.1R14.4
Ivanti Connect Secure version 9.1R17.2
Ivanti Connect Secure version 9.1R18.3
Ivanti Connect Secure version 22.4R2.2
Ivanti Connect Secure version 22.5R1.1
Ivanti Connect Secure version 22.5R2.2
Patched Versions:
Ivanti Connect Secure version 9.1R14.5
Ivanti Connect Secure version 9.1R17.3
Ivanti Connect Secure version 9.1R18.4
Ivanti Connect Secure version 22.4R2.3
Ivanti Connect Secure version 22.5R1.2
Ivanti Connect Secure version 22.5R2.3
Ivanti Connect Secure version 22.6R2.2
Note: This QID does not check for Ivanti Policy Secure or ZTA gateway version.
QID Detection Logic:
This QID checks for installed version of Ivanti Connect Secure (ICS) by sending a GET request to the '/dana-cached/sc/PulseSecureInstallerService.exe' endpoint.
Successful exploitation of the vulnerability may allow an unauthenticated, remote attacker to bypass authentication and gain access to restricted resources without authentication.
CVEs related to QID 731145
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 000090576 |
|