{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2024-21893",
  "revision": 1,
  "title": "Ivanti Connect Secure — Unauthenticated SSRF in the SAML Component",
  "summary": "A server-side request forgery (SSRF) flaw in the Security Assertion Markup Language (SAML) component of Ivanti Connect Secure, Policy Secure and Neurons lets an unauthenticated attacker reach restricted resources through the appliance.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 8.2,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
    "version": "3.1"
  },
  "epss": 0.99999,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2024-01-31",
    "prerequisites": "Network access to an affected Ivanti Connect Secure or Policy Secure appliance (9.x, 22.x) or Neurons for zero trust access. No credentials needed."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Patch Connect Secure, Policy Secure and Neurons per Ivanti's advisory, or take the appliance out of service; hunt for compromise before trusting it again.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "title",
        "summary",
        "cvss",
        "severity",
        "exploitation.attack_complexity",
        "exploitation.prerequisites",
        "exploitation.exploit_available",
        "remediation.patch_available",
        "references"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-21893",
      "retrieved_at": "2026-08-07T07:53:55.549Z",
      "confidence": "high",
      "extractor": "claude-code"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "recommended_action"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-08-07T07:53:55.549Z",
      "confidence": "high",
      "extractor": "claude-code"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2024-21893",
      "retrieved_at": "2026-08-07T07:53:55.549Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21893",
      "label": "NVD record"
    },
    {
      "type": "vendor_advisory",
      "url": "https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US",
      "label": "Ivanti advisory"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21893",
      "label": "CISA Known Exploited Vulnerabilities entry"
    }
  ],
  "published_at": "2024-01-31T18:15:47.437Z",
  "issued_at": "2026-08-07T07:53:55.549Z",
  "tags": [
    "ivanti",
    "connect-secure",
    "policy-secure",
    "vpn",
    "ssrf",
    "kev",
    "ransomware"
  ]
}
