HIGH
CVE-2023-46805
CVSS
8.2
KEV
Description
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
Summary dbcve.org
CVE-2023-46805 is an authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure. The flaw allows remote attackers to bypass control checks and access restricted resources without proper authentication.
Mitigation
Apply vendor-provided patches for Ivanti ICS and Policy Secure to remediate the authentication bypass. If patches are unavailable, implement additional access controls and monitor for unauthorized access attempts to restricted web resources.
Weakness (CWE)
CWE-287
Improper Authentication
EPSS Score
99.99%
Probability of exploitation in next 30 days
100th percentile
References
http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry
https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46805
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.