216.73.217.22

CVE-2024-21893

· Published 31/01/2024 01:00 · Modified 27/05/2026 21:40 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2024-21893

Essential information

Published
31/01/2024 01:00
Modified
27/05/2026 21:40
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
8.2 HIGH (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:L/A:N

CVSS metrics

Description

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.

NVD status

NVD
View on NVD