QID 150791
Date Published: 2024-02-12
QID 150791: Ivanti Connect Secure, Ivanti Policy Secure and Ivanti Neurons for ZTA Server-Side Request Forgery (SSRF) Vulnerability (CVE-2024-21893)
Ivanti Connect Secure (ICS) formerly known as Pulse Connect Secure, is a Remote Access VPN solution, and Ivanti Policy Secure is a Network Access Control (NAC) solution developed by Ivanti.
A Server-Side Request Forgery (SSRF) vulnerability exists in the SAML component which allows an attacker to access certain restricted resources without authentication.
Affected versions:
Ivanti Connect Secure (ICS) and Ivanti Policy Secure versions 9.x and 22.x
QID Detection Logic (Unauthenticated):
This QID sends an HTTP POST request to "dana-ws/saml20.ws" with crafted XML data containing Out-of-band (OOB) payload where vulnerable servers will make a DNS query that will trigger Qualys Periscope detection mechanism.
Successful exploitation of this vulnerability allows an attacker to access certain restricted resources without authentication.
CVEs related to QID 150791
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Ivanti 000090322 |
|