National Cyber Warfare Foundation (NCWF) Forums


Warning: New Ivanti Auth Bypass Flaw Affects Connect Secure and ZTA Gateways


0 user ratings
2024-02-09 04:02:10
milo
Blue Team (CND)

 - archive -- 
Ivanti has alerted customers of yet another high-severity security flaw in its Connect Secure, Policy Secure, and ZTA gateway devices that could allow attackers to bypass authentication.
The issue, tracked as CVE-2024-22024, is rated 8.3 out of 10 on the CVSS scoring system.
"An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti



Source: TheHackerNews
Source Link: https://thehackernews.com/2024/02/warning-new-ivanti-auth-bypass-flaw.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



© Copyright 2012 through 2024 - National Cyber War Foundation - All rights reserved worldwide.