Description

The Ivanti Connect Secure, Policy Secure Gate and Neurons have an SSRF (server-side request forgery) vulnerability. An attacker can use this vulnerability to bypass the fix for the authentication bypass vulnerability (CVE-2023-46805) and exploit the RCE vulnerability (CVE-2024-21887) to compromise the system.

Remediation

Upgrade to the latest version of Ivanti Connect Secure / Policy Secure / Neurons

References

Related Vulnerabilities