logo

Warning: New Ivanti Auth Bypass Flaw Affects Connect Secure and ZTA Gateways

ID: bb95085c-763c-555e-ba19-ed379e3f002c

STIX ID: report--bb95085c-763c-555e-ba19-ed379e3f002c

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-02-09

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Ivanti disclosed CVE-2024-22024, an XXE vulnerability in the SAML component of Ivanti Connect Secure, Policy Secure, and ZTA gateway appliances (CVSS 8.3) that could allow attackers to bypass authentication. Multiple affected versions are listed and patches have been released; Ivanti reports no evidence of active exploitation, but security researchers note the issue resulted from an incorrect fix for a prior bug and can enable SSRF, local file read, and DoS impacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.