peter bassill · operator
$ cve CVE-2024-21893 JSON

CVE-2024-21893 KEV

8.2
HIGH · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2024-02-02.

Description

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

Scoring

CVSS8.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-918
On CISA KEVyes — remediate by 2024-02-02
Public exploitnone known
Published2024-01-31
Last modified2026-08-04

CISA KEV

NameIvanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability
Added2024-01-31
Due2024-02-02
Vendor / productIvanti / Connect Secure, Policy Secure, and Neurons
Ransomware useknown

Affected (3)

VendorProduct
ivanticonnect secure
ivantineurons for zero-trust access
ivantipolicy secure

References

→ the Explorer  ·  watch your stack  ·  NVD