CVE-2024-21893

Ivanti Connect Secure, Policy Secure, and Neurons — Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability
⚠️ CVSS 3.1  8.2 / 10 — HIGH 🔴 CISA Known Exploited Vulnerability

Overview

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.

https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2024-21893

Key Details

PropertyValue
CVE ID CVE-2024-21893
Vendor / Product Ivanti — Connect Secure, Policy Secure, and Neurons
NVD Published2024-01-31
NVD Last Modified2025-10-30
CVSS 3.1 Score8.2
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
SeverityHIGH
CWE CWE-918
CISA KEV Added2024-01-31
CISA KEV Deadline2024-02-02
Known Ransomware Use ⚠️ Yes

CVSS 3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Required Action

CISA BOD 22-01 Deadline: 2024-02-02. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Timeline

DateEvent
2024-01-31Added to CISA Known Exploited Vulnerabilities catalog
2024-02-02CISA BOD 22-01 remediation deadline

References

ResourceType
NVD — CVE-2024-21893 Vulnerability Database
CISA KEV Catalog Entry US Government