CVE-2023-46805 is a high-severity authentication bypass vulnerability affecting the web components of Ivanti Connect Secure and Ivanti Policy Secure appliances. This flaw allows unauthenticated remote attackers to bypass control checks through low-complexity network requests, enabling unauthorized access to restricted internal resources. The vulnerability is actively exploited in the wild, appearing in the CISA Known Exploited Vulnerabilities (KEV) catalog and linked to ransomware campaigns, while the availability of public exploit modules in tools like Metasploit further elevates the risk profile.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.0:*:*:*:*:*:*:* | ||
9.1CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.1:r1:*:*:*:*:*:* | ||
9.1CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.1:r10:*:*:*:*:*:* | ||
9.1CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.1:r11:*:*:*:*:*:* | ||
9.1CPE matchmatch criteria | cpe:2.3:a:ivanti:connect_secure:9.1:r11.3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.