EXPOSURES › CVE-2024-21893
CVE-2024-21893
CRITICAL ⌖ ON CISA KEV · EXPLOITEDIvanti Connect Secure, Policy Secure, and Neurons suffered an actively exploited SSRF vulnerability in their SAML component that bypassed authentication to access restricted resources.
An SSRF flaw in the SAML component of Ivanti's security products allowed attackers to access restricted resources without authentication, and it is actively exploited in the wild. DIB organizations must ensure these products are patched immediately to prevent unauthorized access and potential data exfiltration. This failure highlights the severe risk of relying on unpatched, known vulnerabilities in critical security infrastructure.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating severe negligence and a failure to protect critical security infrastructure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |