5.3

CVE-2024-22023

An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a limited-time DoS. 
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Connect Secure Version 9.1 Update r1
Ivanti ≫ Connect Secure Version 9.1 Update r10
Ivanti ≫ Connect Secure Version 9.1 Update r11
Ivanti ≫ Connect Secure Version 9.1 Update r11.5
Ivanti ≫ Connect Secure Version 9.1 Update r12
Ivanti ≫ Connect Secure Version 9.1 Update r13
Ivanti ≫ Connect Secure Version 9.1 Update r14 SwEdition lts
Ivanti ≫ Connect Secure Version 9.1 Update r15
Ivanti ≫ Connect Secure Version 9.1 Update r16
Ivanti ≫ Connect Secure Version 9.1 Update r17
Ivanti ≫ Connect Secure Version 9.1 Update r18
Ivanti ≫ Connect Secure Version 9.1 Update r2
Ivanti ≫ Connect Secure Version 9.1 Update r3
Ivanti ≫ Connect Secure Version 9.1 Update r4
Ivanti ≫ Connect Secure Version 9.1 Update r4.1
Ivanti ≫ Connect Secure Version 9.1 Update r4.2
Ivanti ≫ Connect Secure Version 9.1 Update r4.3
Ivanti ≫ Connect Secure Version 9.1 Update r5
Ivanti ≫ Connect Secure Version 9.1 Update r6
Ivanti ≫ Connect Secure Version 9.1 Update r7
Ivanti ≫ Connect Secure Version 9.1 Update r8
Ivanti ≫ Connect Secure Version 9.1 Update r9
Ivanti ≫ Connect Secure Version 22.1
Ivanti ≫ Connect Secure Version 22.2
Ivanti ≫ Connect Secure Version 22.3
Ivanti ≫ Connect Secure Version 22.4
Ivanti ≫ Connect Secure Version 22.5
Ivanti ≫ Connect Secure Version 22.6
Ivanti ≫ Policy Secure Version 9.0 Update -
Ivanti ≫ Policy Secure Version 9.0 Update r1
Ivanti ≫ Policy Secure Version 9.0 Update r2
Ivanti ≫ Policy Secure Version 9.0 Update r2.1
Ivanti ≫ Policy Secure Version 9.0 Update r3
Ivanti ≫ Policy Secure Version 9.0 Update r3.1
Ivanti ≫ Policy Secure Version 9.0 Update r4
Ivanti ≫ Policy Secure Version 9.1 Update -
Ivanti ≫ Policy Secure Version 9.1 Update r1
Ivanti ≫ Policy Secure Version 9.1 Update r10
Ivanti ≫ Policy Secure Version 9.1 Update r11
Ivanti ≫ Policy Secure Version 9.1 Update r12
Ivanti ≫ Policy Secure Version 9.1 Update r13
Ivanti ≫ Policy Secure Version 9.1 Update r14
Ivanti ≫ Policy Secure Version 9.1 Update r15
Ivanti ≫ Policy Secure Version 9.1 Update r16
Ivanti ≫ Policy Secure Version 9.1 Update r17
Ivanti ≫ Policy Secure Version 9.1 Update r18
Ivanti ≫ Policy Secure Version 9.1 Update r2
Ivanti ≫ Policy Secure Version 9.1 Update r3
Ivanti ≫ Policy Secure Version 9.1 Update r4
Ivanti ≫ Policy Secure Version 9.1 Update r5
Ivanti ≫ Policy Secure Version 9.1 Update r6
Ivanti ≫ Policy Secure Version 9.1 Update r7
Ivanti ≫ Policy Secure Version 9.1 Update r8
Ivanti ≫ Policy Secure Version 9.1 Update r9
Ivanti ≫ Policy Secure Version 22.1
Ivanti ≫ Policy Secure Version 22.2
Ivanti ≫ Policy Secure Version 22.3
Ivanti ≫ Policy Secure Version 22.4
Ivanti ≫ Policy Secure Version 22.5
Ivanti ≫ Policy Secure Version 22.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3% 0.856
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
HackerOne 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

CWE-703 Improper Check or Handling of Exceptional Conditions

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

https://forums.ivanti.com/s/article/New-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US
Vendor Advisory