CVE-2024-21893: Ivanti Connect Secure, Policy Secure, and Neurons
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability. Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.
- CISA KEV-listed (remediation due 2024-02-02)
- used in ransomware campaigns
- EPSS 94.3% (100.0% percentile)