CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2024-21893

🔥 Known Exploited (CISA KEV)HIGH
8.2
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2024-01-31
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

Affected Platforms (CPE)

📦
Ivanti

Connect Secure

= 9.0= 9.1= 21.9= 21.12= 22.1= 22.2= 22.3= 22.4= 22.6
📦
Ivanti

Policy Secure

= 9.0= 9.1= 22.1= 22.2= 22.3= 22.4= 22.5= 22.6
📦
Ivanti

Neurons For Zero Trust Access

All versions= 22.2= 22.3= 22.4= 22.5= 22.6

References & Advisories

相關漏洞威脅