S4E just found a medium-severity finding from self signed ssl certificate detection
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 30, 2024

CVE-2024-21893 Scanner

Detects 'SSRF' vulnerability in Ivanti Connect Secure affects v. 9.x, 22.x.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-21893
8.2
CVSShigh
Exploitable remotely over the internet · no authentication required.

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ICSby Ivanti
9.1R18
IPSby Ivanti
9.1R18
connect_secureby ivanti
9.0
connect_secureby ivanti
22.6
Updated Aug 22, 2026View on NVD →
Detail

Ivanti Connect Secure is a widely used remote access solution that enables secure connections to corporate networks and resources. It is utilized by organizations and enterprises to facilitate remote work capabilities while maintaining robust security measures. The SAML component of Ivanti Connect Secure is integral for providing authentication and access control in remote access scenarios, ensuring secure connections for users accessing corporate resources from external locations.

The vulnerability detected in Ivanti Connect Secure is a Server Side Request Forgery (SSRF) flaw present in the SAML component. This vulnerability allows an attacker to manipulate server-side requests sent by the application, potentially accessing restricted resources without proper authentication. By exploiting SSRF, an attacker can bypass access controls and interact with internal systems or retrieve sensitive information accessible to the server.

The SSRF vulnerability is triggered by sending a crafted SOAP request to the '/dana-ws/saml20.ws' endpoint of Ivanti Connect Secure. The attacker can control the contents of the SOAP request, including the destination URI, allowing them to request access to internal resources or sensitive endpoints. Successful exploitation of this vulnerability can lead to unauthorized access to restricted resources and compromise the security of the affected system.

Exploiting this SSRF vulnerability can enable an attacker to bypass authentication controls and access sensitive internal resources, potentially leading to data exfiltration, privilege escalation, or further compromise of the network infrastructure. Attackers could leverage SSRF to interact with internal systems, retrieve confidential information, or launch subsequent attacks against other systems within the network.

By leveraging the security scanning capabilities of the S4E platform, you can proactively detect and mitigate critical vulnerabilities like SSRF in Ivanti Connect Secure. Join our platform to ensure the security of your remote access infrastructure and protect your organization from potential data breaches and unauthorized access attempts.

 

References

Solution Advice
  • Apply the latest security patches or updates provided by Ivanti to address the SSRF vulnerability.
  • Implement proper input validation and sanitization mechanisms to prevent malicious input from being processed by the SAML component.
  • Configure network firewalls and access controls to restrict outbound requests from the application to trusted destinations.
  • Regularly monitor server logs for signs of SSRF attacks or unusual network activity indicative of attempted exploitation.
  • Educate system administrators and developers about SSRF vulnerabilities and best practices for secure application development to prevent similar security issues in the future.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.