⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.. Due date: 2024-02-02.

CVE-2024-21893Server-Side Request Forgery in Ivanti ICS

Severity
8.2HIGHNVD
EPSS
94.3%
top 0.05%
CISA KEV
KEVRansomware
Added 2024-01-31
Due 2024-02-02
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJan 31
KEV addedJan 31
KEV dueFeb 2
Latest updateFeb 15
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:NExploitability: 3.9 | Impact: 4.2

Affected Packages5 packages

NVDivanti/policy_secure8 versions+7
NVDivanti/connect_secure9 versions+8
NVDivanti/neurons5 versions+4
CVEListV5ivanti/ics9.1R189.1R18+1
CVEListV5ivanti/ips9.1R189.1R18+1

🔴Vulnerability Details

3
GHSA
GHSA-5rr9-mqhj-7cr2: A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (92024-01-31
CVEList
CVE-2024-21893: A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (92024-01-31
VulnCheck
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability2024

💥Exploits & PoCs

2
Metasploit
Ivanti Connect Secure Unauthenticated Remote Code Execution
Nuclei
Ivanti SAML - Server Side Request Forgery (SSRF)

🔍Detection Rules

1
Suricata
ET EXPLOIT Ivanti Connect Secure (9.x,22.x) / Ivanti Policy Secure (9.x,22.x) / Ivanti Neurons for ZTA SSRF Pattern (CVE-2024-21893)2024-02-02

📋Vendor Advisories

2
CISA
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability2024-01-31
Ivanti
Ivanti Connect Secure SSRF in SAML Component2024-01-31

🕵️Threat Intelligence

9
Bleepingcomputer
Over 13,000 Ivanti gateways vulnerable to actively exploited bugs2024-02-15
Bleepingcomputer
Hackers exploit Ivanti SSRF flaw to deploy new DSLog backdoor2024-02-12
Wiz
Critical Vulnerabilities in Ivanti Exploited In-The-Wild | Wiz Blog2024-02-06
Bleepingcomputer
Newest Ivanti SSRF zero-day now under mass exploitation2024-02-05
Bleepingcomputer
Ivanti warns of new Connect Secure zero-day exploited in attacks2024-01-31
CVE-2024-21893 — Server-Side Request Forgery in Ivanti | cvebase