CVE-2023-46805
Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 January 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- EPSS
- 99.99% probability · 100th percentile
- CISA KEV
- Listed 10 January 2024 · due 22 January 2024 · used in ransomware campaigns
- Weakness
- CWE-287
- Affected
- ivanti/connect secure · ivanti/policy secure
- Source
- support@hackerone.com
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please apply mitigations per vendor instructions. For more information, please see: https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2023-46805
References
- http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_USVendor Advisory
- http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_USVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46805US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.