Vulnerability record · CVE-2023-46805 · published 12 January 2024
CVE-2023-46805: Ivanti Connect Secure and Policy Secure web component authentication bypass
Ivanti · Connect Secure
The web component of Ivanti Connect Secure (ICS) 9.x and 22.x and Ivanti Policy Secure fails to properly enforce authentication, letting a remote attacker reach restricted resources by bypassing control checks. Because these are edge gateways, a bypass exposes internal-facing functionality to the internet without credentials.
Description
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Automated analysis
critical priorityIt is an unauthenticated network-reachable authentication bypass on internet-facing security gateways, listed in KEV with known ransomware use and near-maximum EPSS.
What it is
The web component of Ivanti Connect Secure (ICS) 9.x and 22.x and Ivanti Policy Secure fails to properly enforce authentication, letting a remote attacker reach restricted resources by bypassing control checks. Because these are edge gateways, a bypass exposes internal-facing functionality to the internet without credentials.
Impact
An unauthenticated attacker gains access to restricted resources and functionality on the gateway, providing a foothold that can be chained with other flaws (the vendor advisory pairs it with a command injection issue) toward remote code execution.
Attack surface
Reached over the network via the web component; the CVSS vector shows no privileges required and no user interaction, so it is exploitable pre-authentication by anyone who can reach the gateway interface.
Exploitation
CISA added it to KEV on 2024-01-10 with a 2024-01-22 remediation due date and flags known ransomware campaign use; EPSS is near-certain (0.99986, ~99.98th percentile) and a public exploit reference exists.
What to do
- Apply the vendor's patches or prescribed mitigations for Ivanti Connect Secure and Policy Secure per the Ivanti advisory, and discontinue use if no mitigation is available.
- Isolate or restrict management and external interfaces of the gateways until patched.
- Hunt for and remove any attacker-planted webshells or persistence before or during remediation, since bypass alone does not clean a compromised appliance.
- Reset credentials and review gateway configuration for unauthorized changes after patching.
- Monitor vendor and CISA guidance for updated mitigation steps given the paired command injection flaw.
Detection
- Review gateway and web logs for requests to restricted or administrative paths that succeed without prior authentication.
- Alert on anomalous or unexpected outbound connections and process activity on the appliance.
- Scan the appliance filesystem for modified or added files and known webshell indicators.
- Correlate gateway access logs with authentication logs to find access events lacking a matching login.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-46805 to the Known Exploited Vulnerabilities catalog on 10 January 2024 as "Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 22 January 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Con | Vendor Advisory |
| http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Con | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46805 | US Government Resource |
Track CVE-2023-46805 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-46805), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.