KEVIntel
8.2
CVSS
High

CVE-2024-21893

PUBLISHED

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and...

Exploited in the wild Used in malware PoC available Remote Low complexity No user interaction
Vendor
Ivanti
Product
ICS, IPS
Published
Jan 31, 2024
EPSS

Description

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

cisa malware nuclei_scanner edge metasploit

CVSS scores

CVSS v3.0 8.2 High

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Exploitation status

Exploited in the wild

Recorded 2024-01-31 00:00:00 UTC · Source

Used in malware

Recorded 2026-06-02 14:08:23 UTC · Source

Proof of concept available

Recorded 2024-02-03 11:33:40 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jan 31, 2024

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Chocapikk/CVE-2024-21893-to-CVE-2024-21887

github · Created 2024-02-03 11:33:40 UTC · 26 stars

CVE-2024-21893 to CVE-2024-21887 Exploit Toolkit

h4x0r-dz/CVE-2024-21893.py

github · Created 2024-02-02 22:59:21 UTC · 90 stars

CVE-2024-21893: SSRF Vulnerability in Ivanti Connect Secure

Timeline

  • CVE ID Reserved

  • Added to KEVIntel

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Detected by Nuclei

  • Detected by Metasploit

  • Exploit Used in Malware