id: CVE-2024-21893 info: name: Ivanti SAML - Server Side Request Forgery (SSRF) author: DhiyaneshDk severity: high description: | A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication. impact: | Unauthenticated attackers can perform SSRF attacks to access restricted internal resources and bypass authentication mechanisms. remediation: | Update Ivanti Connect Secure, Policy Secure, and Neurons for ZTA to the latest patched versions. reference: - https://attackerkb.com/topics/FGlK1TVnB2/cve-2024-21893/rapid7-analysis - https://www.assetnote.io/resources/research/ivantis-pulse-connect-secure-auth-bypass-round-two - https://github.com/advisories/GHSA-5rr9-mqhj-7cr2 - https://github.com/Chocapikk/CVE-2024-21893-to-CVE-2024-21887 - https://github.com/Ostorlab/KEV classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N cvss-score: 8.2 cve-id: CVE-2024-21893 cwe-id: CWE-918 epss-score: 0.94319 epss-percentile: 0.99952 cpe: cpe:2.3:a:ivanti:connect_secure:9.0:-:*:*:*:*:*:* metadata: max-request: 1 vendor: ivanti product: connect_secure shodan-query: - "html:\"welcome.cgi?p=logo\"" - http.title:"ivanti connect secure" - http.html:"welcome.cgi?p=logo" fofa-query: - body="welcome.cgi?p=logo" - title="ivanti connect secure" google-query: intitle:"ivanti connect secure" tags: cve,cve2024,kev,ssrf,ivanti,vkev,vuln http: - raw: - | POST /dana-ws/saml20.ws HTTP/1.1 Host: {{Hostname}} qwerty matchers-condition: and matchers: - type: word part: interactsh_protocol # Confirms the DNS Interaction words: - "dns" - type: word part: body words: - '/dana-na/' - 'WriteCSS' condition: and # digest: 4a0a00473045022100ea361ee375c2ad827eca2fbc066a5d26c324bfe3217d90123959cad9594c6bfb02202bf1fdb558659487b5665bdaca4de893e027e41d5889bedd9306c41830316d23:922c64590222798bb761d5b6d8e72950