Skip to content
    CVE-2023-46805criticalKEVEXPLOITRANSOMWAREZERO DAYInitial AccessSecurin Validate-Ready

    Security Update for Ivanti Connect Secure and Ivanti Policy Secure Gateways

    An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

    Vulnerability Type
    Improper Access Control
    Impact Type
    Authentication/Authorization Bypass
    Vector
    NETWORK
    Affected Vendors
    ivanti +1 more
    9.52CriticalSecurin Risk Score
    CVSS: 8.2

    Vulnerability Timeline

    1. CVE Published
    2. 1st Exploit Published
    3. Securin Predicted
    4. Securin KEV Published
    5. CISA KEV Published
    6. NVD Published
    • Securin Predicted → NVD Latency: 367 days
    • Securin Predicted → CISA Latency: Up to 1 Day
    • Securin Predicted → Exploit Latency: 7 days

    Threat Intelligence Summary

    An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

    Weaknesses
    Threats
    17
    Threat Actor Associations

    References

    CVE

    Exploit

    Unlock the details for this CVE

    Sign up with Securin to access the full AI summary, impacted products, exploitability details, threat intelligence, discussions and reference mappings for this CVE.

    Unlock with Securin