Vulnerability Description
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a limited-time DoS.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Connect Secure | 9.1 |
| Ivanti | Policy Secure | 9.0 |
Related Weaknesses (CWE)
References
- https://forums.ivanti.com/s/article/New-CVE-2024-21894-Heap-Overflow-CVE-2024-22Vendor Advisory
- https://forums.ivanti.com/s/article/New-CVE-2024-21894-Heap-Overflow-CVE-2024-22Vendor Advisory
FAQ
What is CVE-2024-22023?
CVE-2024-22023 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests i...
How severe is CVE-2024-22023?
CVE-2024-22023 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-22023?
Check the references section above for vendor advisories and patch information. Affected products include: Ivanti Connect Secure, Ivanti Policy Secure.