Junglewise Threat Intelligence

CVE-2024-21893: Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

CVE-2024-21893 · Severity: critical · CVSS 8.2 · Exploited in the wild · Published 2024-01-31

Technologies: Ivanti Connect Secure, Ivanti Policy Secure, Ivanti Neurons. Vendors: Ivanti.

Executive brief

A server-side request forgery (SSRF) vulnerability exists in the SAML component of Ivanti Connect Secure, Policy Secure, and Neurons for ZTA. This flaw allows unauthenticated remote attackers to access restricted resources by sending specially crafted requests.

Affected products

  • Ivanti Connect Secure 9.x, 22.x
  • Ivanti Policy Secure 9.x, 22.x
  • Ivanti Neurons for ZTA All versions

Timeline

  • 2024-01-31: disclosed
  • 2024-01-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-01-31: exploited: Reported as exploited in the wild at time of publication.

Related threats