An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
CVE ID: CVE-2024-22024
CVSS Base Severity: HIGH
CVSS Base Score: 8.3
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Vendor: Ivanti, Ivant
Product: ICS, IPS
http/cves/2024/CVE-2024-22024.yaml
EPSS Score: 94.32% (probability of being exploited)
EPSS Percentile: 99.94% (scored less or equal to compared to others)
EPSS Date: 2025-06-07 (when was this score calculated)
SSVC Exploitation: poc
SSVC Technical Impact: partial
SSVC Automatable: true