Skip to main content

Cybersecurity Weather

Global observatory

← Vulnerabilities

CVE-2024-21893

EPSS 100%KEV

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.

Published
Last modified
CISA KEV
Yes
Ransomware use
Known

Official sources

CVE-2024-21893 | Cyber Weather Index