CVE-2023-46805
CVE Published | 2024-01-12 |
---|---|
Related CWE(s) | CWE-287: Improper Authentication |
Related Vendor(s) | ivanti |
Related Product(s) | connect_secure, policy_secure |
Exploitation Reported (CISA KEV) | 2024-01-10 |
CVSS 3 Base Score | 8.2 (HIGH) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph
Threat Reports Related to CVE-2023-46805
Report
Magnet Goblin Targets Publicly Facing Servers Using 1-Day Vulnerabilities - Check Point Research
This blog post from CheckPoint Research describes a campaign targeting Ivanti, Magento, Qlink Sense and possibly Apache ActiveMQ systems which ...
Report
Ivanti Connect Secure: Journey to the core of the DSLog backdoor
The CERT at Orange report on the exploitation of multiple vulnerabilities in Ivanti products. Following successful exploitation, the attackers ...