CVE-2023-46805
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
- Affected products
- Ivanti Connect Secure, Ivanti Policy Secure
- Ivanti Connect Secure
- = 9.0, 9.1, 22.1, 22.2, 22.3, 22.4, 22.5, 22.6
- Ivanti Policy Secure
- = 9.0, 9.1, 22.1, 22.2, 22.3, 22.4, 22.5, 22.6
- CVSS 3.1
- 8.2 HIGH
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-287
- NVD status
- Analyzed
- Published
- 2024-01-12
CVE-2023-46805 at NVD
21 known exploits for CVE-2023-46805
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2023-46805_CVE-2024-21887
CVE-2023-46805_CVE-2024-21887
CVE-2023-46805
CVE-2023-46805
CVE-2023-21887
CVE-2023-46805
Exploit for Deserialization of Untrusted Data in Facebook React
Ivanti Connect Secure Unauthenticated Remote Code Execution Exploit
Ivanti Connect Secure Unauthenticated Remote Code Execution
Exploit for Improper Authentication in Ivanti Connect_Secure
Ivanti Connect Secure Unauthenticated Remote Code Execution Exploit
Ivanti Connect Secure Unauthenticated Remote Code Execution
Exploit for Improper Authentication in Ivanti Connect_Secure
Exploit for Improper Authentication in Ivanti Connect_Secure
Ivanti Connect Secure and Policy Secure authentication bypass and command injection
Ivanti Connect Secure and Policy Secure authentication bypass and command injection
Exploit for Improper Authentication in Ivanti Connect_Secure
Exploit for Improper Authentication in Ivanti Connect_Secure
Exploit for Improper Authentication in Ivanti Connect_Secure
Exploit for Improper Authentication in Ivanti Connect_Secure
Ivanti Connect Secure Unauthenticated Remote Code Execution