CVE-2024-22023: XEE
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a limited-time DoS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22023?
CVE-2024-22023 has a severity rating that indicates a potential for temporary resource exhaustion and a limited Denial of Service (DoS) for affected systems.
How do I fix CVE-2024-22023?
To address CVE-2024-22023, it is recommended that users apply the latest security patches provided by Ivanti for affected versions of Connect Secure and Policy Secure.
Which versions of Ivanti software are affected by CVE-2024-22023?
CVE-2024-22023 affects Ivanti Connect Secure versions 9.x and 22.x, as well as Ivanti Policy Secure versions 9.x and 22.x.
Can CVE-2024-22023 be exploited remotely?
Yes, an unauthenticated attacker can exploit CVE-2024-22023 remotely by sending specially crafted XML requests.
What type of attack is CVE-2024-22023 associated with?
CVE-2024-22023 is associated with XML Entity Expansion (XEE) attacks that can lead to resource exhaustion.