CVE-2024-21893
ID: 3e31c5ea-3d02-557c-b3ab-28e8746ffe3e
STIX ID: report--3e31c5ea-3d02-557c-b3ab-28e8746ffe3e
Feed Name: Arctic Wolf Blog
Arctic Wolf warns of two high-severity Ivanti vulnerabilities—CVE-2024-21893 (server-side request forgery in SAML) and CVE-2024-21888 (privilege escalation)—affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons; the advisory recommends upgrading to fixed versions or importing a mitigation XML and running integrity checks. While no public proof-of-concept or widespread exploitation has been observed for these specific CVEs, the alert cites recent zero-day activity against Ivanti products and assesses that threat actors are likely to attempt targeting these vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
