CVE-2024-22023: Ivanti Connect Secure
Medium severity, CVSS 5.3. EPSS: 3% chance of exploitation in the next 30 days.
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a limited-time DoS.
Affected products
- Ivanti Connect Secure: version 9.1 only; version 22.1 only; version 22.2 only; version 22.3 only; version 22.4 only; version 22.5 only; …
- Ivanti Policy Secure: version 9.0 only; version 9.1 only; version 22.1 only; version 22.2 only; version 22.3 only; version 22.4 only; …
Published 2024-04-04. Last modified 2026-06-17.