CVE-2024-21893

Ivanti ICS, Ivanti IPS, ivanti connect_secure

Published 31 Jan 2024 · updated 4 Aug 2026 · Analyzed

8.2 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 31 Jan 2024, with a remediation deadline of 2 Feb 2024 for US federal agencies. It has been used in ransomware campaigns.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

References