CyberSec.Space Logo
Back to CVE Browser

CVE-2024-21893

🔥 Known Exploited (CISA KEV)HIGH
8.2
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2024-01-31
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

Affected Platforms (CPE)

📦
Ivanti

Connect Secure

= 9.0= 9.1= 21.9= 21.12= 22.1= 22.2= 22.3= 22.4= 22.6
📦
Ivanti

Policy Secure

= 9.0= 9.1= 22.1= 22.2= 22.3= 22.4= 22.5= 22.6
📦
Ivanti

Neurons For Zero Trust Access

All versions= 22.2= 22.3= 22.4= 22.5= 22.6

References & Advisories

Related Vulnerabilities