HTTP: Ivanti Endpoint Manager ImportXml XML External Entity Injection

This signature detects attempts to exploit a known vulnerability against Ivanti. A successful attack can lead to sensitive information disclosure.

Extended Description

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.

Short Name
HTTP:CTS:IVANTI-ENDPNT-MNGR
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2024-37397 Endpoint Entity External ImportXml Injection Ivanti Manager XML
Release Date
11/11/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3757
False Positive
Unknown

Found a potential security threat?