CVE-2024-21893
Ivanti ICS, Ivanti IPS, ivanti connect_secure
Published 31 Jan 2024 · updated 4 Aug 2026 · Analyzed
8.2 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 31 Jan 2024, with a remediation deadline of 2 Feb 2024 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.