TROYANOSYVIRUS
Back to CVEs

CVE-2023-46805

HIGHCISA KEV
8.2

Description

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

CVE Details

CVSS v3.1 Score8.2
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published1/12/2024
Last Modified10/31/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorIvanti
ProductConnect Secure and Policy Secure
Vulnerability NameIvanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
KEV Date Added2024-01-10
Remediation Due Date2024-01-22
Ransomware UseKnown

Affected Products

ivanti:connect_secureivanti:policy_secure

Weaknesses (CWE)

CWE-287

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.