US government agencies ordered to take Ivanti VPN products offline

US government agencies ordered to take Ivanti VPN products offline

However, on January 31 Ivanti disclosed two more vulnerabilities that were discovered while investigating the previous two flaws: a privilege escalation vulnerability tracked as (CVE-2024-21888) and a server-side request forgery in the SAML component (CVE-2024-21893). The latter can…

source website