CVE-2024-21893
Ivanti ICS
Summary
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authen…
Published: 2024-01-31
Analysis
🟠 High — imminent exploitation
Weakness: Server-Side Request Forgery (SSRF) (CWE-918). Forces the server to make requests to internal targets.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Confidentiality high · Integrity partial · Availability none.
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The vector encodes how it's exploited (translated above, in the analysis). Break it down in the CVSS tool →
Sources: CISA KEV · EPSS · FIRST.org · NVD. Analysis derived from the CVSS vector and exploitation status (no AI). Informational; always verify against the vendor's official advisory.