Description Preview
Overview
The vulnerability affects multiple versions of Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS) products. Specifically, versions 9.x and 22.x of these products are impacted by the XXE vulnerability. The affected versions include 9.1R14.5, 9.1R17.3, 9.1R18.4, 22.1R6.1, and others. The vulnerability has been assigned a CVSS base score of 8.3, indicating a high severity level.
Remediation
To mitigate the CVE-2024-22024 vulnerability, users and administrators are advised to apply the necessary security patches provided by Ivanti for the affected versions of Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS). It is recommended to update the affected systems to versions that are not vulnerable to the XXE flaw. Additionally, organizations should review and adjust their security configurations to prevent exploitation of XXE vulnerabilities in the future.
References
For more information on CVE-2024-22024 and remediation steps, refer to the following resource:
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Public AdministrationPublic Administration
- ManufacturingManufacturing
- Health Care & Social AssistanceHealth Care & Social Assistance
- Other Services (except Public Administration)Other Services (except Public Administration)
- Educational ServicesEducational Services
- Transportation & WarehousingTransportation & Warehousing
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- Finance and InsuranceFinance and Insurance
- Retail TradeRetail Trade
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- ConstructionConstruction
- UtilitiesUtilities
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- InformationInformation
- MiningMining
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Wholesale TradeWholesale Trade