Ivanti urges customers to patch yet another critical vulnerability
ID: 05efd3e7-8a20-5bae-9d52-7c9217f4d141
STIX ID: report--05efd3e7-8a20-5bae-9d52-7c9217f4d141
Feed Name: Malwarebytes Blog
Ivanti disclosed an XXE vulnerability (CVE-2024-22024, CVSS 8.3) in specific versions of Connect Secure, Policy Secure, and ZTA gateways that can allow access to restricted resources without authentication; patches and detailed KB mitigation instructions are available for supported versions and customers are urged to apply them immediately. Ivanti reports no evidence of exploitation of this CVE to date, but multiple other Ivanti vulnerabilities have been actively exploited, and CISA previously advised disconnecting vulnerable Ivanti products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
