Security
Loading…

CVE-2023-46805

HIGHCVSS 8.2Known Exploited
Description

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.

Timeline
Published:January 12th, 2024 5:15 PM
Last modified:August 4th, 2026 5:16 AM
Added to KEV:January 10th, 2024
CVSS Scoring

CVSS v3: 8.2 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Affected Software
From NVD CPE configuration data

Vendors

ivanti

Products

connect_securepolicy_secure
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute