CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
CWE-287
HIPAA-164.306(a)
ISO27001-A.13.1.1
OWASP 2013-A9
OWASP 2017-A9
PCI v3.2-6.5.1
WASC-1

Authentication Bypass in Ivanti Connect Secure and Policy Secure (CVE-2023-46805)

Severity:
High
Summary

Invicti detected Authentication Bypass vulnerability.

The Ivanti Connect Secure and Ivanti Policy Secure have an authentication bypass vulnerability.
An attacker can bypass the authentication with a specially crafted HTTP request
and get administrative access to the system.

Impact

An unauthenticated attacker can compromise the Ivanti Connect Secure / Policy Secure.

Remediation

Upgrade to the latest version of Ivanti Connect Secure / Policy Secure

Required Skills for Successful Exploitation
Actions To Take
Vulnerability Index

You can search and find all vulnerabilities

Featured resources

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding