8.2

CVE-2024-21893

Warning

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

Data is provided by the National Vulnerability Database (NVD)
IvantiConnect Secure Version9.0 Update-
IvantiConnect Secure Version9.0 Updater1
IvantiConnect Secure Version9.0 Updater2
IvantiConnect Secure Version9.0 Updater2.1
IvantiConnect Secure Version9.0 Updater3
IvantiConnect Secure Version9.0 Updater3.1
IvantiConnect Secure Version9.0 Updater3.2
IvantiConnect Secure Version9.0 Updater3.3
IvantiConnect Secure Version9.0 Updater3.5
IvantiConnect Secure Version9.0 Updater4
IvantiConnect Secure Version9.0 Updater4.1
IvantiConnect Secure Version9.0 Updater5.0
IvantiConnect Secure Version9.0 Updater6.0
IvantiConnect Secure Version9.1 Updater1
IvantiConnect Secure Version9.1 Updater10
IvantiConnect Secure Version9.1 Updater11
IvantiConnect Secure Version9.1 Updater11.3
IvantiConnect Secure Version9.1 Updater11.4
IvantiConnect Secure Version9.1 Updater11.5
IvantiConnect Secure Version9.1 Updater12
IvantiConnect Secure Version9.1 Updater12.1
IvantiConnect Secure Version9.1 Updater13
IvantiConnect Secure Version9.1 Updater13.1
IvantiConnect Secure Version9.1 Updater14
IvantiConnect Secure Version9.1 Updater15
IvantiConnect Secure Version9.1 Updater15.2
IvantiConnect Secure Version9.1 Updater16
IvantiConnect Secure Version9.1 Updater16.1
IvantiConnect Secure Version9.1 Updater17
IvantiConnect Secure Version9.1 Updater17.1
IvantiConnect Secure Version9.1 Updater18
IvantiConnect Secure Version9.1 Updater18.1
IvantiConnect Secure Version9.1 Updater18.2
IvantiConnect Secure Version9.1 Updater2
IvantiConnect Secure Version9.1 Updater3
IvantiConnect Secure Version9.1 Updater4
IvantiConnect Secure Version9.1 Updater4.1
IvantiConnect Secure Version9.1 Updater4.2
IvantiConnect Secure Version9.1 Updater4.3
IvantiConnect Secure Version9.1 Updater5
IvantiConnect Secure Version9.1 Updater6
IvantiConnect Secure Version9.1 Updater7
IvantiConnect Secure Version9.1 Updater8
IvantiConnect Secure Version9.1 Updater8.1
IvantiConnect Secure Version9.1 Updater8.2
IvantiConnect Secure Version9.1 Updater9
IvantiConnect Secure Version9.1 Updater9.1
IvantiConnect Secure Version21.9 Updater1
IvantiConnect Secure Version21.12 Updater1
IvantiConnect Secure Version22.1 Updater1
IvantiConnect Secure Version22.1 Updater6
IvantiConnect Secure Version22.2 Update-
IvantiConnect Secure Version22.2 Updater1
IvantiConnect Secure Version22.3 Updater1
IvantiConnect Secure Version22.4 Updater1
IvantiConnect Secure Version22.4 Updater2.1
IvantiConnect Secure Version22.6 Update-
IvantiConnect Secure Version22.6 Updater1
IvantiConnect Secure Version22.6 Updater2
IvantiConnect Secure Version22.6 Updater2.1
IvantiPolicy Secure Version9.0 Update-
IvantiPolicy Secure Version9.0 Updater1
IvantiPolicy Secure Version9.0 Updater2
IvantiPolicy Secure Version9.0 Updater2.1
IvantiPolicy Secure Version9.0 Updater3
IvantiPolicy Secure Version9.0 Updater3.1
IvantiPolicy Secure Version9.0 Updater4
IvantiPolicy Secure Version9.1 Update-
IvantiPolicy Secure Version9.1 Updater1
IvantiPolicy Secure Version9.1 Updater10
IvantiPolicy Secure Version9.1 Updater11
IvantiPolicy Secure Version9.1 Updater12
IvantiPolicy Secure Version9.1 Updater13
IvantiPolicy Secure Version9.1 Updater13.1
IvantiPolicy Secure Version9.1 Updater14
IvantiPolicy Secure Version9.1 Updater15
IvantiPolicy Secure Version9.1 Updater16
IvantiPolicy Secure Version9.1 Updater17
IvantiPolicy Secure Version9.1 Updater18
IvantiPolicy Secure Version9.1 Updater18.1
IvantiPolicy Secure Version9.1 Updater18.2
IvantiPolicy Secure Version9.1 Updater2
IvantiPolicy Secure Version9.1 Updater3
IvantiPolicy Secure Version9.1 Updater3.1
IvantiPolicy Secure Version9.1 Updater4
IvantiPolicy Secure Version9.1 Updater4.1
IvantiPolicy Secure Version9.1 Updater4.2
IvantiPolicy Secure Version9.1 Updater4.3
IvantiPolicy Secure Version9.1 Updater5
IvantiPolicy Secure Version9.1 Updater6
IvantiPolicy Secure Version9.1 Updater7
IvantiPolicy Secure Version9.1 Updater8
IvantiPolicy Secure Version9.1 Updater8.1
IvantiPolicy Secure Version9.1 Updater8.2
IvantiPolicy Secure Version9.1 Updater9
IvantiPolicy Secure Version22.1 Updater1
IvantiPolicy Secure Version22.1 Updater6
IvantiPolicy Secure Version22.2 Updater1
IvantiPolicy Secure Version22.2 Updater3
IvantiPolicy Secure Version22.3 Updater1
IvantiPolicy Secure Version22.3 Updater3
IvantiPolicy Secure Version22.4 Updater1
IvantiPolicy Secure Version22.4 Updater2
IvantiPolicy Secure Version22.4 Updater2.1
IvantiPolicy Secure Version22.5 Updater1
IvantiPolicy Secure Version22.6 Updater1
IvantiNeurons For Zero-trust Access Version22.2 Updater1
IvantiNeurons For Zero-trust Access Version22.2 Updater4
IvantiNeurons For Zero-trust Access Version22.2 Updater5
IvantiNeurons For Zero-trust Access Version22.3 Updater1
IvantiNeurons For Zero-trust Access Version22.3 Updater4
IvantiNeurons For Zero-trust Access Version22.4 Updater1
IvantiNeurons For Zero-trust Access Version22.4 Updater3
IvantiNeurons For Zero-trust Access Version22.5 Updater1
IvantiNeurons For Zero-trust Access Version22.5 Updater1.2
IvantiNeurons For Zero-trust Access Version22.6 Updater1
IvantiNeurons For Zero-trust Access Version22.6 Updater1.2

31.01.2024: CISA Known Exploited Vulnerabilities (KEV) Catalog

Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.

Description

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 94.32% 0.999
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.2 3.9 4.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
support@hackerone.com 8.2 3.9 4.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.