← Vulnerability feed

Vulnerability record · CVE-2024-21893 · published 31 January 2024

CVE-2024-21893: Ivanti Connect Secure SAML SSRF allows unauthenticated resource access

Ivanti · Connect Secure

The SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reach restricted resources without authentication. Because the affected products are internet-facing gateways, the flaw matters for perimeter security and was added to CISA KEV with a two-day remediation deadline.

8.2 CVSS 3.1 High CISA KEV since 31 Jan 2024 Known ransomware use EPSS 100% · top 0.1% CWE-918 · Server-side request forgery (SSRF)
8.2CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
3References
4 Aug 2026Last modified by NVD

Description

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe flaw is unauthenticated, network-reachable, listed in CISA KEV with known ransomware use, and has an EPSS probability near 1.0.

What it is

The SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reach restricted resources without authentication. Because the affected products are internet-facing gateways, the flaw matters for perimeter security and was added to CISA KEV with a two-day remediation deadline.

Impact

An unauthenticated attacker can make the appliance issue requests to restricted internal resources, potentially reaching services not otherwise exposed. The CVSS vector rates confidentiality impact as high and integrity impact as low, with no availability impact.

Attack surface

Reachable over the network through the SAML component with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed SAML endpoint on the listed products is in scope.

Exploitation

Listed in CISA KEV on 2024-01-31 with known ransomware campaign use, and EPSS probability is effectively 1.0, indicating active exploitation. No public exploit references are included in the record beyond the vendor advisory and KEV entry.

What to do

  • Apply the vendor's patches or prescribed mitigations for the SAML SSRF immediately, per the KEV required action.
  • If no mitigation is available, discontinue use of the affected appliance as CISA directs.
  • Restrict or monitor external access to SAML endpoints on Connect Secure, Policy Secure and Neurons for ZTA.
  • Isolate management and internal interfaces from the internet-facing SAML path to limit SSRF reach.
  • Review KEV guidance and vendor advisories for updated remediation steps.

Detection

  • Monitor appliance and perimeter logs for anomalous outbound requests originating from the SAML service to internal addresses.
  • Alert on SAML endpoint requests from unexpected source IPs or with malformed SAML payloads.
  • Correlate appliance egress traffic with internal service access logs for signs of SSRF-driven requests.
  • Hunt for post-exploitation activity consistent with KEV-listed ransomware use on affected appliances.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-21893 to the Known Exploited Vulnerabilities catalog on 31 January 2024 as "Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 2 February 2024.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-21893 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2023-46805Ivanti Connect Secure and Policy Secure web component authentication bypassThe web component of Ivanti Connect Secure (ICS) 9.x and 22.x and Ivanti Policy Secure fails to properly enforce authentication, letting a remote att…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-21893), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.