Article Details
Scrape Timestamp (UTC): 2024-02-09 03:39:40.048
Source: https://thehackernews.com/2024/02/warning-new-ivanti-auth-bypass-flaw.html
Original Article Text
Click to Toggle View
Warning: New Ivanti Auth Bypass Flaw Affects Connect Secure and ZTA Gateways. Ivanti has alerted customers of yet another high-severity security flaw in its Connect Secure, Policy Secure, and ZTA gateway devices that could allow attackers to bypass authentication. The issue, tracked as CVE-2024-22024, is rated 8.3 out of 10 on the CVSS scoring system. "An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication," the company said in an advisory. The company said it discovered the flaw during an internal review as part of its ongoing investigation into multiple security weaknesses in the products that have come to light since the start of the year, including CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, and CVE-2024-21893. CVE-2024-22024 affects the following versions of the products - Patches for the bug are available in Connect Secure versions 9.1R14.5, 9.1R17.3, 9.1R18.4, 22.4R2.3, 22.5R1.2, 22.5R2.3, and 22.6R2.2; Policy Secure versions 9.1R17.3, 9.1R18.4, and 22.5R1.2; and ZTA versions 22.5R1.6, 22.6R1.5, and 22.6R1.7. Ivanti said there is no evidence of active exploitation of the flaw, but with CVE-2023-46805, CVE-2024-21887, and CVE-2024-21893 coming under broad abuse, it's imperative that users move quickly to apply the latest fixes. ⚡ Free Risk Assessment from Vanta Generate a gap assessment of your security and compliance posture, discover shadow IT, and more.
Daily Brief Summary
Ivanti has reported a high-severity authentication bypass vulnerability, designated as CVE-2024-22024, affecting their security products.
The vulnerability scores 8.3/10 on the CVSS scale and could allow unrestricted access to certain resources without authentication.
Affected products include Ivanti Connect Secure, Policy Secure, and ZTA gateways, specifically in the SAML component due to an XXE issue.
The flaw was identified during an ongoing internal review that has unveiled multiple security issues in Ivanti products this year.
Ivanti has released patches for various versions of the affected products to address this vulnerability.
The company notes there is no current evidence of active exploitation but urges users to update promptly due to recent abuse of other Ivanti vulnerabilities.