HackerFeeds
All CVEs

CVE-2023-46805

HIGH8.2
CISA KEV

Published 2024-01-12 · Updated 2026-08-04 · Source support@hackerone.com

Description

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CWE-287

CISA Known-Exploited Vulnerability

Product: IvantiConnect Secure and Policy Secure

Name: Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

Date added: 2024-01-10 · Due: 2024-01-22

USED IN RANSOMWARE

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

View on NVD