CVE-2024-21893
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
| Vendor | ivanti |
| Product | ics |
| Ecosystems | |
| Industries | SecurityNetworking |
| Published | Jan 31, 2024 |
| Last Updated | Oct 21, 2025 |
⚠️ Actively Exploited — Act Now
Get instant alerts for ivanti ics
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2024-21893.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Affected Versions
Ivanti / ICS
9.1R18 ≤ 9.1R18 22.6R2 ≤ 22.6R2
Ivanti / IPS
9.1R18 ≤ 9.1R18 22.6R1 ≤ 22.6R1