Start with Identity
Identity CVE · SAML

CVE-2024-21893Ivanti Connect Secure SAML SSRF, chained to auth bypass

criticalCISA KEVActively exploited
Product: Ivanti Connect Secure / Policy SecureVendor: IvantiCWE-918Disclosed: 2024-01-31Status: Actively exploitedProtocol deep diveNVD ↗CISA KEV ↗

What broke

The SAML stack on Ivanti Connect Secure (9.x, 22.x) and Policy Secure would fetch attacker-controlled URLs (SSRF). After the January 2024 patches for CVE-2023-46805 (auth bypass) and CVE-2024-21887 (command injection), attackers used this SAML SSRF as the leftover door. CISA added it to KEV. watchTowr and Rapid7 published the chain.

Why it matters

VPN concentrators are identity enforcement points. When the SAML ACS can be turned into an SSRF, "we federated login" becomes "the IdP conversation is an attack primitive." This is why FortiCloud SSO and Ivanti keep landing on the same page of this catalog.

What to do

  • Patch ICS/IPS for CVE-2024-21893 even if you already took the 46805 / 21887 builds.
  • If the box was internet-facing in January–February 2024, assume compromise. Rebuild, do not just patch.
  • Hunt for unexpected XML from the SAML ACS, new local admins, and outbound connections from the appliance.
  • Disable SAML on the appliance if you do not need it. A VPN that does local auth is better than a VPN whose ACS is an SSRF.

Sources

Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.