Evidence dossier

CVE-2024-21893

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an…

Exploited in the wild (CISA KEV since Jan 31, 2024). NVD reports CVSS 3.1 8.2. EPSS estimates 100.0% exploit likelihood as of Jul 18, 2026.

80.595.5Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

State
PUBLISHED
Published
Jan 31, 2024
Updated
Aug 4, 2026
Evidence coverage
85%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability
    Original evidence ↗
  2. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 100% probability · 100th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.999990000000; percentile 0.999990000000
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  4. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  5. Source dateSource date omittedFirst observed by CASCA
    hackerone

    Record text: A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

    Inspect raw assertion
    Field
    container
    Value
    A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Jan 31, 2024 · first observed Jul 19, 2026

Exploit likelihood100.00%

FIRST EPSS · score date Jul 18, 2026 · 100th percentile · first observed Jul 19, 2026

SeverityCVSS 8.2

NVD · CVSS 3.1 · first observed Aug 4, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA KEVOriginal assertion
Exploitation cataloged

Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

100% probability · 100th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.999990000000; percentile 0.999990000000
Source dateFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
hackeroneOriginal assertion
Record text

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

Inspect raw assertion
Field
container
Value
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
118Underlying assertions
3Canonical products
118Target assertions
0Constraint assertions

Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

22 scope groups

CISA-ADP · source assertedivanticonnect_secureDirect source scope
Affected: 9.0
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "9.0"}]
CISA-ADP · source assertedivanticonnect_secureDirect source scope
Affected: 22.6
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "22.6"}]
CISA-ADP · source assertedivanticonnect_secureDirect source scope
Affected: 22.1
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "22.1"}]
CISA-ADP · source assertedivanticonnect_secureDirect source scope
Affected: 22.2
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "22.2"}]
CISA-ADP · source assertedivanticonnect_secureDirect source scope
Affected: 9.1
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "9.1"}]
CISA-ADP · source assertedivanticonnect_secureDirect source scope
Affected: 21.9
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "21.9"}]
CISA-ADP · source assertedivanticonnect_secureDirect source scope
Affected: 21.12
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "21.12"}]
CISA-ADP · source assertedivanticonnect_secureDirect source scope
Affected: 22.4
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "22.4"}]
CISA-ADP · source assertedivanticonnect_secureDirect source scope
Affected: 22.3
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "22.3"}]
CISA-ADP · source assertedivantipolicy_secureDirect source scope
Affected: 9.1
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "9.1"}]
CISA-ADP · source assertedivantipolicy_secureDirect source scope
Affected: 9.0
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "9.0"}]
CISA-ADP · source assertedivantipolicy_secureDirect source scope
Affected: 22.2
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "22.2"}]
CISA-ADP · source assertedivantipolicy_secureDirect source scope
Affected: 22.3
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "22.3"}]
CISA-ADP · source assertedivantipolicy_secureDirect source scope
Affected: 22.6
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "22.6"}]
CISA-ADP · source assertedivantipolicy_secureDirect source scope
Affected: 22.5
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "22.5"}]
CISA-ADP · source assertedivantipolicy_secureDirect source scope
Affected: 22.4
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "22.4"}]
CISA-ADP · source assertedivantipolicy_secureDirect source scope
Affected: 22.1
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "22.1"}]
hackerone · source assertedIvantiICSDirect source scope
Affected: 9.1R18 through 9.1R18 (semver comparison)Affected: 22.6R2 through 22.6R2 (semver comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "9.1R18", "versionType": "semver", "lessThanOrEqual": "9.1R18"}, {"status": "affected", "version": "22.6R2", "versionType": "semver", "lessThanOrEqual": "22.6R2"}]
hackerone · source assertedIvantiIPSDirect source scope
Affected: 9.1R18 through 9.1R18 (semver comparison)Affected: 22.6R1 through 22.6R1 (semver comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "9.1R18", "versionType": "semver", "lessThanOrEqual": "9.1R18"}, {"status": "affected", "version": "22.6R1", "versionType": "semver", "lessThanOrEqual": "22.6R1"}]
NVD CPE · APPLICATIONivanticonnect_secureVulnerable target · 60 assertions
Version 21.12; Version 21.9; Version 22.1; Version 22.2; Version 22.3; Version 22.4; Version 22.6; Version 9.0; Version 9.1Canonical identity product-0675def37879dcf14a27022586db7f5234f5d2c3f293e3a70a47a5da19da3b1bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:ivanti:connect_secure:9.1:r4.3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0349a0cc-a372-4e51-899e-d7ba67876f4b
  2. cpe:2.3:a:ivanti:connect_secure:9.1:r15.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d7dbcd6b-b7aa-4ab0-852f-563a2ec85db4
  3. cpe:2.3:a:ivanti:connect_secure:9.0:r4.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    24ef2f1a-8140-4fdb-8af4-309afaf998e1
  4. cpe:2.3:a:ivanti:connect_secure:9.0:r3.3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    59f4a6f7-a6d4-4517-a316-7c7c002a9ed3
  5. cpe:2.3:a:ivanti:connect_secure:22.1:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 49
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    80c56782-273a-4151-be81-13feefe46a6a
  6. cpe:2.3:a:ivanti:connect_secure:9.0:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3818b543-3415-4e27-8dad-6ba9d3d9a1a5
  7. cpe:2.3:a:ivanti:connect_secure:9.0:r2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    59331dc5-ff5f-4bb3-905e-5a4a621f86ed
  8. cpe:2.3:a:ivanti:connect_secure:9.0:r5.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4755bc2c-a96e-47af-9d7c-e8d44b31f10b
  9. cpe:2.3:a:ivanti:connect_secure:9.0:r3.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f05dc11e-7c41-450b-a2bf-603e9252bb40
  10. cpe:2.3:a:ivanti:connect_secure:22.4:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 54
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e9f55e7b-7b38-4aec-a015-d8cb9de5e72c
  11. cpe:2.3:a:ivanti:connect_secure:9.1:r12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    32e0b425-a9ba-4d00-84a9-46268072d696
  12. cpe:2.3:a:ivanti:connect_secure:9.1:r8.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bffa0b02-7f6d-4434-b1e7-eb8520fd68a0
  13. cpe:2.3:a:ivanti:connect_secure:9.1:r16:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    44c26423-8621-4f6d-a45b-0a6b6e873ab6
  14. cpe:2.3:a:ivanti:connect_secure:21.9:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 47
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bd52b87c-4bed-44ae-a959-a316daf895ec
  15. cpe:2.3:a:ivanti:connect_secure:22.2:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 52
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bcbf6dd0-2826-4e61-8fb6-db489ebf8981
  16. cpe:2.3:a:ivanti:connect_secure:9.1:r2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4fefc4b1-7350-46f9-80c1-42f5ae06142f
  17. cpe:2.3:a:ivanti:connect_secure:22.6:r2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 58
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5456f61d-1fd1-4da6-afa3-4073889ad22a
  18. cpe:2.3:a:ivanti:connect_secure:22.3:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 53
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    415219d0-2d9a-4617-abb7-6ff918421bee
  19. cpe:2.3:a:ivanti:connect_secure:22.1:r6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 50
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6564fe9e-7d96-4226-8378-dac25525cdd1
  20. cpe:2.3:a:ivanti:connect_secure:22.6:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 57
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ab9a5868-34fb-446e-817f-6701cc5de923
  21. cpe:2.3:a:ivanti:connect_secure:9.1:r6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3ccc2d7b-f835-45ec-a316-2f0c5f2cf565
  22. cpe:2.3:a:ivanti:connect_secure:9.0:r6.0:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bf6e8a0c-192b-4f51-86aa-fc2b85657632
  23. cpe:2.3:a:ivanti:connect_secure:9.1:r8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9fa0b20d-3fa1-42ae-bdc5-93d8a182927c
  24. cpe:2.3:a:ivanti:connect_secure:22.6:r2.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 59
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ea574551-14bf-45e1-ac2a-2fb5b265640e
  25. cpe:2.3:a:ivanti:connect_secure:9.1:r18.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db2b8165-e9d4-4549-b16e-a62810bdaf8d
  26. cpe:2.3:a:ivanti:connect_secure:9.0:r4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a369ae09-17e4-4541-a8e1-a2f4a1398ee7
  27. cpe:2.3:a:ivanti:connect_secure:9.0:r3.5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    702094b0-2e5c-4a16-a8b0-f0eaf78e4ecb
  28. cpe:2.3:a:ivanti:connect_secure:9.1:r18.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    080cd832-3324-4158-a4cd-3a2e49b7bc74
  29. cpe:2.3:a:ivanti:connect_secure:9.1:r3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db7a6d62-6576-4713-9bf4-11068a72e8b7
  30. cpe:2.3:a:ivanti:connect_secure:9.1:r7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ad812596-c77c-4129-982f-c22a25b52126
  31. cpe:2.3:a:ivanti:connect_secure:22.6:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 56
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6c383863-1e90-4b72-a500-4326782bc92f
  32. cpe:2.3:a:ivanti:connect_secure:9.1:r9.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 46
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b2c10c89-1dbc-4e91-bd28-d5097b589ca9
  33. cpe:2.3:a:ivanti:connect_secure:9.1:r11.4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6f2a7f5c-1d78-4d19-b8ed-5822fdf5da63
  34. cpe:2.3:a:ivanti:connect_secure:9.1:r8.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 44
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dfe8fa87-9622-4d5b-99c7-d8ee230c0aa9
  35. cpe:2.3:a:ivanti:connect_secure:9.1:r17.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e238ab9f-99c1-4f0d-b442-d390065d35d1
  36. cpe:2.3:a:ivanti:connect_secure:9.0:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d47d09a8-4ac4-4cd9-b648-5f26453e2e1d
  37. cpe:2.3:a:ivanti:connect_secure:9.1:r17:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db6cea16-f422-48f1-9473-3931b1bfa63f
  38. cpe:2.3:a:ivanti:connect_secure:9.0:r2.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6a708c3f-9050-4475-95b3-4785d3e2cb69
  39. cpe:2.3:a:ivanti:connect_secure:9.1:r11.3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    366ef5b8-0233-49b8-806a-e54f60410ade
  40. cpe:2.3:a:ivanti:connect_secure:9.1:r12.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bbc724e8-195b-4cb4-ac2a-63e184aed4f6
  41. cpe:2.3:a:ivanti:connect_secure:9.1:r4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    843bc1b9-50cc-4f8f-a454-a0cec6e92290
  42. cpe:2.3:a:ivanti:connect_secure:9.1:r18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    28fde909-711c-41ec-8ba6-ac4de05ea27e
  43. cpe:2.3:a:ivanti:connect_secure:9.1:r11.5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2ddda231-2a5e-4c70-8620-535c7f9027a4
  44. cpe:2.3:a:ivanti:connect_secure:9.1:r13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    65435a96-ef7a-439a-aa6c-cb7eaef0a963
  45. cpe:2.3:a:ivanti:connect_secure:9.1:r15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ce228fbd-5ad1-4bc6-af63-5248e671b04f
  46. cpe:2.3:a:ivanti:connect_secure:9.1:r4.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3de32a0c-8944-4f51-a286-266055ca4b2f
  47. cpe:2.3:a:ivanti:connect_secure:9.0:r3.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5da976d9-a330-475e-b8c0-09ef3e08f18d
  48. cpe:2.3:a:ivanti:connect_secure:9.1:r9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 45
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    16daa769-8f0d-4c54-a8d9-9902995605b0
  49. cpe:2.3:a:ivanti:connect_secure:9.1:r16.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bc391eb5-c457-459c-8eaa-ea0043487c0b
  50. cpe:2.3:a:ivanti:connect_secure:9.1:r11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8d5f47ba-de6d-443d-95c3-a45f80edc71e
  51. cpe:2.3:a:ivanti:connect_secure:9.1:r13.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3027a9ce-849e-4cae-a1c4-170deaf4fe86
  52. cpe:2.3:a:ivanti:connect_secure:9.1:r4.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d5355372-03ea-46d7-9104-a2785c29b664
  53. cpe:2.3:a:ivanti:connect_secure:9.1:r10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5a3a93fe-41bf-43f2-9efc-89656182329f
  54. cpe:2.3:a:ivanti:connect_secure:9.1:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4b21c181-dc49-4ebd-9932-dbb337151ff7
  55. cpe:2.3:a:ivanti:connect_secure:22.4:r2.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 55
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d3df17ac-ec26-4b76-8989-b7880c9ef73e
  56. cpe:2.3:a:ivanti:connect_secure:9.1:r5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    93d1a098-bd77-4a7b-9070-a764fb435981
  57. cpe:2.3:a:ivanti:connect_secure:22.2:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 51
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    361faa47-52ff-4b36-96b0-9c178a4e031b
  58. cpe:2.3:a:ivanti:connect_secure:9.1:r14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c132ba26-bca0-43e6-9511-34acffa136a9
  59. cpe:2.3:a:ivanti:connect_secure:21.12:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 48
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8ca29f12-36de-4fbf-9ee7-7ce4b75afa61
  60. cpe:2.3:a:ivanti:connect_secure:9.0:r3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    52851aaa-88fb-40bc-b41a-b821f6ba9f79
NVD CPE · APPLICATIONivantineurons_for_zero-trust_accessVulnerable target · 12 assertions
Version 22.2; Version 22.3; Version 22.4; Version 22.5; Version 22.6; Version not applicableCanonical identity product-e90f3997d7cc4df6275e905ffcd39c4194e810e779fb51d8b68d7e4b8a3bf923Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.6:r1.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    62a0393a-c1c6-4708-bc41-5a5b8fb765ff
  2. cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.3:r4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9f28e6b1-44ab-4635-8939-5b0a44bed1e6
  3. cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.3:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7b01001b-fa11-4297-ab81-12a00b97c820
  4. cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.2:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    24514b40-540e-45d7-90dc-bcc1d9d7e92c
  5. cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.6:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    58e49df1-f66a-4f52-87fa-a50dfd735ecb
  6. cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.4:r3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d1ab497e-e403-4dee-a83d-cb2e119e5e96
  7. cpe:2.3:a:ivanti:neurons_for_zero-trust_access:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0e4387b4-bc5c-41de-92da-84866a649ad2
  8. cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.4:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3e9d957b-49f9-492d-a66a-0d25ba27ad35
  9. cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.2:r4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bfd510e9-12dc-4942-baa0-6405cbd905ef
  10. cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.5:r1.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    47cb7c12-d642-4015-842c-37241f87db86
  11. cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.2:r5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ea11bb6d-36c7-438b-a5a7-71c3cb2e5ec8
  12. cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.5:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ca6b3322-9afb-44b5-b571-995ab606fd01
NVD CPE · APPLICATIONivantipolicy_secureVulnerable target · 46 assertions
Version 22.1; Version 22.2; Version 22.3; Version 22.4; Version 22.5; Version 22.6; Version 9.0; Version 9.1Canonical identity product-66735516e7e23282d6cbb1b21ef896b9b737013272849d8db9227bbeb2d5728aLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:ivanti:policy_secure:9.1:r4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 84
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c9a5ba3e-d6b3-453d-8ddf-ff16859fd0f8
  2. cpe:2.3:a:ivanti:policy_secure:9.1:r7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 90
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ac3863bc-3b9a-402b-a74a-149cdf717ec6
  3. cpe:2.3:a:ivanti:policy_secure:9.1:r18.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 79
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    98fc67f0-3eef-4c69-bb94-a15b1fe4d8f3
  4. cpe:2.3:a:ivanti:policy_secure:9.1:r12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 71
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fe5c4abc-2beb-4741-95b3-303903369818
  5. cpe:2.3:a:ivanti:policy_secure:22.1:r6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 96
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    925dccba-9382-4a39-84b8-4deafd2bc802
  6. cpe:2.3:a:ivanti:policy_secure:9.1:r16:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 76
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b90687f3-a5c1-4706-ad66-d78ee512e4c9
  7. cpe:2.3:a:ivanti:policy_secure:9.0:r2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 62
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    aa514c05-2834-4c7b-b022-02b41c9aad6a
  8. cpe:2.3:a:ivanti:policy_secure:9.1:r14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 74
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7a53c031-e7a5-47b6-ba4a-dd28432e743f
  9. cpe:2.3:a:ivanti:policy_secure:9.1:r3.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 83
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    38a0d7cf-7d55-4933-ae8c-36006d6779e1
  10. cpe:2.3:a:ivanti:policy_secure:9.1:r9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 94
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    092da2a3-5cef-433f-8e5b-4850e4095cc4
  11. cpe:2.3:a:ivanti:policy_secure:9.1:r3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 82
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fc2b9da0-e32b-4125-9986-f0d3814c66e9
  12. cpe:2.3:a:ivanti:policy_secure:9.1:r18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 78
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    811c7e7e-89ab-47df-bacd-ed478df756bc
  13. cpe:2.3:a:ivanti:policy_secure:9.1:r13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 72
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d50c5526-f791-4c76-b5c0-da2e1281c9e2
  14. cpe:2.3:a:ivanti:policy_secure:22.4:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 101
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d73729eb-c679-4ced-9f36-212b0581ec22
  15. cpe:2.3:a:ivanti:policy_secure:22.6:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 105
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    56c7542d-3520-4e4d-936c-5295068c4cd7
  16. cpe:2.3:a:ivanti:policy_secure:9.1:r17:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 77
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d10a3f2d-6a62-4a48-93fb-274527c821d2
  17. cpe:2.3:a:ivanti:policy_secure:22.5:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 104
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cb4b1ed6-38ad-44f8-9b77-2d6924e8a20e
  18. cpe:2.3:a:ivanti:policy_secure:9.1:r8.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 93
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7ed1686b-2d80-4ecf-9f7a-aea989e17c84
  19. cpe:2.3:a:ivanti:policy_secure:9.1:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 68
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a07b66e0-a679-4912-8cb1-cd134713edc7
  20. cpe:2.3:a:ivanti:policy_secure:22.2:r3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 98
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1536db45-9a42-4549-a10e-fdbb6693df17
  21. cpe:2.3:a:ivanti:policy_secure:9.0:r3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 64
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0d36cb5a-8389-4f2f-882a-4e8f30028799
  22. cpe:2.3:a:ivanti:policy_secure:9.1:r2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 81
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6d37a6e4-d58e-444d-af6a-15461f38e81a
  23. cpe:2.3:a:ivanti:policy_secure:9.1:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 67
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6418a649-3a63-40cc-bd7c-309b3b0b2595
  24. cpe:2.3:a:ivanti:policy_secure:9.1:r4.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 86
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d55ab5f0-132f-4c40-bf4f-684e139b774b
  25. cpe:2.3:a:ivanti:policy_secure:9.1:r13.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 73
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2cb8240e-7683-4c39-9654-4f8d1f682288
  26. cpe:2.3:a:ivanti:policy_secure:9.1:r5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 88
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6be937d2-8bee-4e64-8738-f550ead00f50
  27. cpe:2.3:a:ivanti:policy_secure:9.1:r10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 69
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bf767f07-2e9f-4099-829d-2f70e85d8a35
  28. cpe:2.3:a:ivanti:policy_secure:9.0:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 61
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    26b25b34-7bd0-471b-a396-45ce5420e963
  29. cpe:2.3:a:ivanti:policy_secure:9.1:r4.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 85
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bafda618-d15d-401d-ac68-0020259fec57
  30. cpe:2.3:a:ivanti:policy_secure:22.4:r2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 102
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    14b481e8-d887-408f-b892-d2939cd037ab
  31. cpe:2.3:a:ivanti:policy_secure:22.2:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 97
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    34c118fb-7ae0-466c-822a-348a2f6016ac
  32. cpe:2.3:a:ivanti:policy_secure:22.3:r3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 100
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8bbc1e81-0a2a-4166-bfa6-2b866b4f8ae4
  33. cpe:2.3:a:ivanti:policy_secure:9.1:r8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 91
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e3c09d51-fda0-4d07-87d8-f527c8cbdafb
  34. cpe:2.3:a:ivanti:policy_secure:9.0:r4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 66
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f72c00c7-017c-4c25-99b0-d7d42d969e92
  35. cpe:2.3:a:ivanti:policy_secure:22.1:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 95
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a385f38b-0b03-4b69-b7a1-952f5bae727c
  36. cpe:2.3:a:ivanti:policy_secure:9.1:r8.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 92
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cce2e1c0-680f-4eff-ace6-a1dafa209d24
  37. cpe:2.3:a:ivanti:policy_secure:9.0:r2.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 63
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0929c645-dacb-4341-9032-7c79ffc8bcf0
  38. cpe:2.3:a:ivanti:policy_secure:9.0:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 60
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    afe8db4a-9891-4647-82e2-eb5d377cad25
  39. cpe:2.3:a:ivanti:policy_secure:9.1:r4.3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 87
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    26aeb02e-d2d0-4d7a-bb00-9e5112696b17
  40. cpe:2.3:a:ivanti:policy_secure:22.3:r1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 99
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    51ff66c9-9415-4ead-8f19-d5e067336885
  41. cpe:2.3:a:ivanti:policy_secure:9.1:r6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 89
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9c753520-1bc6-4980-afc9-4c2fddf2fd18
  42. cpe:2.3:a:ivanti:policy_secure:22.4:r2.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 103
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3eb8380f-d229-4af0-b27c-47760f843e48
  43. cpe:2.3:a:ivanti:policy_secure:9.1:r15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 75
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4bee355b-1c2d-4beb-8922-eaeaa5a1fae8
  44. cpe:2.3:a:ivanti:policy_secure:9.1:r18.2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 80
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    77aa3823-7b01-423e-be8e-797aeb567b8f
  45. cpe:2.3:a:ivanti:policy_secure:9.1:r11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 70
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b994e22b-8fa5-4510-82f6-7820bda7c307
  46. cpe:2.3:a:ivanti:policy_secure:9.0:r3.1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 65
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    517da74b-9d69-45e1-a707-a08a305a507c

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

8.2
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
8.2
support@hackerone.comCVSS 3.0 · role Secondary · priority eligiblevalid_matchCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
8.2
hackeroneCVSS 3.0 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.