TROYANOSYVIRUS
Retour aux CVEs

CVE-2024-21893

HIGHCISA KEV
8.2

Description

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

Details CVE

Score CVSS v3.18.2
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie1/31/2024
Derniere modification10/30/2025
Sourcekev
Observations honeypot0

CISA KEV

FournisseurIvanti
ProduitConnect Secure, Policy Secure, and Neurons
Nom vulnerabiliteIvanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability
Date ajout KEV2024-01-31
Date limite remediation2024-02-02
Utilise dans ransomwareKnown

Produits affectes

ivanti:connect_secureivanti:neurons_for_zero-trust_accessivanti:policy_secure

Faiblesses (CWE)

CWE-918CWE-918

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.