Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-21893


A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.


Published

2024-01-31T18:15:47.437

Last Modified

2024-11-29T15:16:27.133

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-918
  • Type: Secondary
    CWE-918

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.0 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 9.1 Yes
Application ivanti connect_secure 21.9 Yes
Application ivanti connect_secure 21.12 Yes
Application ivanti connect_secure 22.1 Yes
Application ivanti connect_secure 22.1 Yes
Application ivanti connect_secure 22.2 Yes
Application ivanti connect_secure 22.2 Yes
Application ivanti connect_secure 22.3 Yes
Application ivanti connect_secure 22.4 Yes
Application ivanti connect_secure 22.4 Yes
Application ivanti connect_secure 22.6 Yes
Application ivanti connect_secure 22.6 Yes
Application ivanti connect_secure 22.6 Yes
Application ivanti connect_secure 22.6 Yes
Application ivanti policy_secure 9.0 Yes
Application ivanti policy_secure 9.0 Yes
Application ivanti policy_secure 9.0 Yes
Application ivanti policy_secure 9.0 Yes
Application ivanti policy_secure 9.0 Yes
Application ivanti policy_secure 9.0 Yes
Application ivanti policy_secure 9.0 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 9.1 Yes
Application ivanti policy_secure 22.1 Yes
Application ivanti policy_secure 22.1 Yes
Application ivanti policy_secure 22.2 Yes
Application ivanti policy_secure 22.2 Yes
Application ivanti policy_secure 22.3 Yes
Application ivanti policy_secure 22.3 Yes
Application ivanti policy_secure 22.4 Yes
Application ivanti policy_secure 22.4 Yes
Application ivanti policy_secure 22.4 Yes
Application ivanti policy_secure 22.5 Yes
Application ivanti policy_secure 22.6 Yes
Application ivanti neurons_for_zero-trust_access - Yes
Application ivanti neurons_for_zero-trust_access 22.2 Yes
Application ivanti neurons_for_zero-trust_access 22.2 Yes
Application ivanti neurons_for_zero-trust_access 22.2 Yes
Application ivanti neurons_for_zero-trust_access 22.3 Yes
Application ivanti neurons_for_zero-trust_access 22.3 Yes
Application ivanti neurons_for_zero-trust_access 22.4 Yes
Application ivanti neurons_for_zero-trust_access 22.4 Yes
Application ivanti neurons_for_zero-trust_access 22.5 Yes
Application ivanti neurons_for_zero-trust_access 22.5 Yes
Application ivanti neurons_for_zero-trust_access 22.6 Yes
Application ivanti neurons_for_zero-trust_access 22.6 Yes

References