CVE-2024-21893 is a critical server-side request forgery (SSRF) vulnerability found in the SAML component of Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA. This flaw allows an unauthenticated attacker to access restricted resources. Rated with a CVSS score of 8.2 (HIGH), it presents a low-complexity attack vector with high impact on confidentiality and moderate impact on integrity. The vulnerability is actively exploited, including in known ransomware campaigns, with public exploit modules available and significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.0:-:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.0:r1:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.0:r2:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.0:r2.1:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.0:r3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.