CVE-2024-21893
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 2 February 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- EPSS
- 100.00% probability · 100th percentile
- CISA KEV
- Listed 31 January 2024 · due 2 February 2024 · used in ransomware campaigns
- Weakness
- CWE-918
- Affected
- ivanti/connect secure · ivanti/policy secure · ivanti/neurons for zero-trust access
- Source
- support@hackerone.com
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2024-21893
References
- https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_USVendor Advisory
- https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_USVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21893US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.