CVE-2024-21893
KEV RANSOMWAREHIGH 8.2EPSS 100.0%
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
- CVSS v3.1
- 8.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N - CVSS v3.0
- 8.2 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-01-31, used in ransomware campaigns
- Nuclei
- high · CWE-918
- Published
- 2024-01-31
- Updated
- 2026-08-04
Proof-of-concept exploits (2)
- Chocapikk/CVE-2024-21893-to-CVE-2024-2188727★ · 2025-04-06
- h4x0r-dz/CVE-2024-21893.py94★ · 2024-02-02