CVE-2024-21893
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- January 03, 2024
- Published Date
- January 31, 2024
- Last Updated
- August 01, 2024
- Vendor
- Ivanti
- Product
- ICS, IPS
- Description
- A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
- Tags
- Exploitation
- Active
- Automatable
- Yes
- Technical Impact
- Partial
CVSS Scores
CVSS v3.0
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
SSVC Information
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2024-01-31 00:00:00 UTC |
Recent Mentions
Verizon 2025 DBIR: Tenable Research Collaboration Shines a Spotlight on CVE Remediation Trends
Source: Tenable Blog • Published: 2025-04-23 04:05:00 UTC
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ivanti_connect_secure_rce_cve_2024_21893.rb | 2025-04-29 11:01:13 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-21893.yaml | 2025-04-26 00:00:00 UTC |
Nessus | https://www.tenable.com/plugins/nessus/190060 | 2024-02-07 14:22:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
Chocapikk/CVE-2024-21893-to-CVE-2024-21887
Type: github • Created: 2024-02-03 11:33:40 UTC • Stars: 26
h4x0r-dz/CVE-2024-21893.py
Type: github • Created: 2024-02-02 22:59:21 UTC • Stars: 90
Timeline
-
CVE ID Reserved
-
Added to KEVIntel
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Detected by Nessus
-
Detected by Nuclei
-
Detected by Metasploit