References https://www.akamai.com/zh/blog/security-research/scanning-activity-ivanti-cve-february-2024 https://lazarusalliance.com/zh-CN/what-are-the-ivanti-vulnerabilities-and-how-do-they-impact-you/ https://www.ithome.com.tw/news/161530 https://cve.imfht.com/poc_detail/5c45c09218f6f97afcf66381dae17b9bfce4cd1c https://cn-sec.com/archives/2528612.html https://blog.csdn.net/m0_71944965/article/details/144559909 https://hub.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure https://nvd.nist.gov/vuln/detail/CVE-2024-22024 https://www.huntress.com/threat-library/vulnerabilities/cve-2024-22024 https://www.cve.org/CVERecord?id=CVE-2024-22024 https://github.com/adysec/POC/blob/main/wpoc/Ivanti/CVE-2024-22024.md https://www.ivanti.com/blog/security-update-for-ivanti-connect-secure-and-ivanti-policy-secure-gateways-282024 https://www.cisa.gov/news-events/directives/ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure-vulnerabilities https://www.hkcert.org/tc/security-bulletin/ivanti-products-security-restriction-bypass-vulnerability_20240209 https://www.tenablecloud.cn/plugins/was/114203 https://unit42.paloaltonetworks.com/threat-brief-ivanti-cve-2023-46805-cve-2024-21887/ https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22024 https://github.com/0dteam/CVE-2024-22024 https://www.paloaltonetworks.com/cyberpedia/ivanti-VPN-vulnerability-what-you-need-to-know https://threatprotect.qualys.com/2024/02/09/ivanti-connect-secure-and-ivanti-policy-secure-xml-external-entity-xxe-vulnerability-cve-2024-22024/ https://www.savetime.com.tw/Symantec-Protection-Bulletin-Weekly.asp https://avd.aliyun.com/detail?id=AVD-2024-22024 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-22024.yaml https://www.ithome.com.tw/news/161326 https://www.govcert.gov.hk/tc/alerts_detail.php?id=1226 https://www.twcert.org.tw/tw/cp-104-7690-f3690-1.html https://www.anquanke.com/post/id/294219 https://www.ncsc.gov.uk/news/exploitation-ivanti-vulnerabilities https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2024-015/ https://www.rapid7.com/blog/post/2024/01/11/etr-zero-day-exploitation-of-ivanti-connect-secure-and-policy-secure-gateways/ https://www.jpcert.or.jp/at/2024/at240002.html https://www.tarlogic.com/blog/cve-2024-22024-xxe-ivanti/
Related VulnerabilitiesPoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code InjectionPoCCVE-2026-10520: Ivanti Sentry - OS Command InjectionIvanti Sentry存在操作系统命令注入漏洞(CVE-2026-10520)Ivanti Sentry /mics/api/v2/sentry/mics-config/handleMessage 命令执行漏洞(CVE-2026-10520)Ivanti EPMM /mifs/rs/api/v2/featureusage 命令执行漏洞(CVE-2025-4427)PoCIvanti Endpoint Manager /RemoteControlAuth/api/Auth 权限绕过漏洞(CVE-2026-1603)Ivanti Endpoint Manager 权限管理不当漏洞PoCCVE-2026-1603: Ivanti Endpoint Manager - Authentication BypassIvanti Endpoint Manager Mobile /mifs/c/appstore/fob/3/5/sha256 命令执行漏洞(CVE-2026-1281/CVE-2026-1340)Ivanti Endpoint Manager Mobile 未授权 代码注入漏洞Ivanti多个产品跨站请求伪造漏洞(CVE-2025-8711)(CVE-2025-8712)Ivanti产品权限验证不足漏洞