HIGH

CVE-2023-46805

Ivanti Connect Secure 2024-01-12 CVSS v3.1
CVSS
8.2
KEV

Description

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

Summary dbcve.org

CVE-2023-46805 is an authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure. The flaw allows remote attackers to bypass control checks and access restricted resources without proper authentication.

Mitigation

Apply vendor-provided patches for Ivanti ICS and Policy Secure to remediate the authentication bypass. If patches are unavailable, implement additional access controls and monitor for unauthorized access attempts to restricted web resources.

Proof of Concept

Weakness (CWE)

CWE-287 Improper Authentication

EPSS Score

99.99%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE