216.73.217.22

CVE-2023-46805

· Published 10/01/2024 01:00 · Modified 27/05/2026 21:40 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2023-46805

Essential information

Published
10/01/2024 01:00
Modified
27/05/2026 21:40
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
8.2 HIGH (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:L/A:N

CVSS metrics

Description

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.

NVD status

NVD
View on NVD