ZeroHour

CVE-2024-21893

KEV ransomwarelarge

SSRF in Ivanti Connect Secure, Policy Secure, and Neurons SAML Component

CISA: Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

CVSS 3.1
8.2 high
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2024-21893 is a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure (formerly Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons. A remote attacker can trigger the flaw with crafted unauthenticated requests to the SAML component, causing the appliance to make requests to otherwise restricted resources. Successful exploitation allows the attacker to access certain restricted resources without any credentials, and CISA notes the flaw has been used in ransomware operations. Any organization running an affected Ivanti Connect Secure, Policy Secure, or Neurons deployment is exposed, particularly where the appliance is reachable from the internet. The vulnerability is confirmed exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-31, carries an EPSS probability of 100%, and no public proof-of-concept is known.

What to do: Apply Ivanti's released patches or the vendor-issued mitigations immediately per vendor instructions, or discontinue use of the product if mitigations are unavailable, as required by CISA. Because ransomware use is documented, review SAML-related logs and appliance audit trails for signs of exploitation and follow-on compromise, and check for indicators of post-exploitation activity. Monitor Ivanti advisories for patched version numbers and updated mitigation guidance, since specific fixed versions are not yet specified in the available data.

Affected
Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti Policy Secure
Ivanti Neurons
Estimated exposure
largetens of thousands of internet-exposed appliances (with total user counts likely in the hundreds of thousands) — Public internet scans during the January 2024 exploitation wave identified tens of thousands of exposed Ivanti Connect Secure/Pulse Secure VPN appliances, and these enterprise VPN gateway products typically serve large user populations…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

CISA Known Exploited Vulnerability
Affected
Ivanti Connect Secure, Policy Secure, and Neurons
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
ivanti
Products
connect secure, policy secure, neurons for zero-trust access
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news