CVE-2023-46805
| CVE Published | 2024-01-12 |
|---|---|
| Related CWE(s) | CWE-287: Improper Authentication |
| Related Vendor(s) | ivanti |
| Related Product(s) | policy_secure, connect_secure |
| Exploitation Reported (CISA KEV) | 2024-01-10 |
| CVSS 3 Base Score | 8.2 (HIGH) |
| CVSS 3 Attack Complexity | LOW |
| CVSS 3 Attack Vector | NETWORK |
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph
Threat Reports Related to CVE-2023-46805
Report
Magnet Goblin Targets Publicly Facing Servers Using 1-Day Vulnerabilities - Check Point Research
This blog post from CheckPoint Research describes a campaign targeting Ivanti, Magento, Qlink Sense and possibly Apache ActiveMQ systems which ...
Report
Ivanti Connect Secure: Journey to the core of the DSLog backdoor
The CERT at Orange report on the exploitation of multiple vulnerabilities in Ivanti products. Following successful exploitation, the attackers ...