CVE-2023-46805: Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
Other sources
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.
— CISA
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-46805?
CVE-2023-46805 is rated as critical due to its potential for authentication bypass, allowing unrestricted access to sensitive information.
What versions are affected by CVE-2023-46805?
CVE-2023-46805 affects Ivanti Connect Secure and Ivanti Policy Secure versions 9.x and 22.x.
How do I fix CVE-2023-46805?
To remediate CVE-2023-46805, users should upgrade to the latest patched versions of Ivanti Connect Secure and Ivanti Policy Secure.
What type of vulnerability is CVE-2023-46805?
CVE-2023-46805 is an authentication bypass vulnerability in the web component of Ivanti's software.
Who can exploit CVE-2023-46805?
CVE-2023-46805 can be exploited by remote attackers without requiring authentication, making it particularly dangerous.