QID 150791

Date Published: 2024-02-12

QID 150791: Ivanti Connect Secure, Ivanti Policy Secure and Ivanti Neurons for ZTA Server-Side Request Forgery (SSRF) Vulnerability (CVE-2024-21893)

Ivanti Connect Secure (ICS) formerly known as Pulse Connect Secure, is a Remote Access VPN solution, and Ivanti Policy Secure is a Network Access Control (NAC) solution developed by Ivanti.

A Server-Side Request Forgery (SSRF) vulnerability exists in the SAML component which allows an attacker to access certain restricted resources without authentication.

Affected versions:
Ivanti Connect Secure (ICS) and Ivanti Policy Secure versions 9.x and 22.x

QID Detection Logic (Unauthenticated):
This QID sends an HTTP POST request to "dana-ws/saml20.ws" with crafted XML data containing Out-of-band (OOB) payload where vulnerable servers will make a DNS query that will trigger Qualys Periscope detection mechanism.

Successful exploitation of this vulnerability allows an attacker to access certain restricted resources without authentication.

  • CVSS V3 rated as Critical - 8.2 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Customers are advised to upgrade to Ivanti Connect Secure versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1 and 22.5R2.2, Ivanti Policy Secure version 22.5R1.1 and ZTA version 22.6R1.3 or later to remediate this vulnerability. For more information, please refer to Ivanti 000090322 and Ivanti KB.

    CVEs related to QID 150791

    Software Advisories
    Advisory ID Software Component Link
    Ivanti 000090322 URL Logo forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US