🔐 CVE Alert

CVE-2024-21893

HIGH 8.2 ⚠️ CISA KEV
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

Vendor ivanti
Product ics
Ecosystems
Industries
SecurityNetworking
Published Jan 31, 2024
Last Updated Oct 21, 2025
⚠️ Actively Exploited — Act Now

Get instant alerts for ivanti ics

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2024-21893.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Affected Versions

Ivanti / ICS
9.1R18 ≤ 9.1R18 22.6R2 ≤ 22.6R2
Ivanti / IPS
9.1R18 ≤ 9.1R18 22.6R1 ≤ 22.6R1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
forums.ivanti.com: https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21893