A AegiFlow
HIGHCVSS 8.2KNOWN EXPLOITEDRANSOMWARE: KNOWN

CVE-2024-21893

CVE-2024-21893 updated by NVD

Published
2024-01-31
Modified
2026-09-21
Sources
cisa-kev, nvd

Summary

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.