CVE-2023-46805criticalKEVEXPLOITRANSOMWAREZERO DAYInitial AccessSecurin Validate-Ready
Security Update for Ivanti Connect Secure and Ivanti Policy Secure Gateways
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
Vulnerability Type
Improper Access Control
Impact Type
Authentication/Authorization Bypass
Vector
NETWORK
Affected Vendors
ivanti +1 more
Securin Risk Score
CVSS: 8.2
Vulnerability Timeline
- CVE Published
- 1st Exploit Published
- Securin Predicted
- Securin KEV Published
- CISA KEV Published
- NVD Published
- Securin Predicted → NVD Latency: 367 days
- Securin Predicted → CISA Latency: Up to 1 Day
- Securin Predicted → Exploit Latency: 7 days
Threat Intelligence Summary
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
Weaknesses
—
Threats
17
Threat Actor Associations
—
References
Unlock the details for this CVE
Sign up with Securin to access the full AI summary, impacted products, exploitability details, threat intelligence, discussions and reference mappings for this CVE.
Unlock with Securin