{"id":"CVE-2023-46805","title":"An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.","summary":"An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","cwe":["CWE-287"],"vendor":"ivanti","product":"connect_secure","affected":["connect_secure = 9.0","connect_secure = 9.1","connect_secure = 22.1","connect_secure = 22.2","connect_secure = 22.3","connect_secure = 22.4","connect_secure = 22.5","connect_secure = 22.6","policy_secure = 9.0","policy_secure = 9.1","policy_secure = 22.1","policy_secure = 22.2","policy_secure = 22.3","policy_secure = 22.4","policy_secure = 22.5","policy_secure = 22.6"],"published":"2024-01-12","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-46805","references":[{"url":"http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html","label":"support@hackerone.com"},{"url":"https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US","label":"support@hackerone.com"},{"url":"http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46805","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.99986,"epssPercentile":0.99983,"kev":true,"kevDateAdded":"2024-01-10","kevDueDate":"2024-01-22","kevRansomware":true,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-04T05:36:12.394Z","exploits":{"github":9,"githubRepos":["https://github.com/yoryio/CVE-2023-46805","https://github.com/cbeek-r7/CVE-2023-46805","https://github.com/duy-31/CVE-2023-46805_CVE-2024-21887"],"metasploit":["exploit/linux/http/ivanti_connect_secure_rce_cve_2023_46805"],"nuclei":["CVE-2023-46805"],"checkedAt":"2026-09-08T15:36:49.901Z"},"exploitAvailable":true,"slug":"CVE-2023-46805","body":"## Overview\n\nAn authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.\n\n## Affected\n\n- `connect_secure = 9.0`\n- `connect_secure = 9.1`\n- `connect_secure = 22.1`\n- `connect_secure = 22.2`\n- `connect_secure = 22.3`\n- `connect_secure = 22.4`\n- `connect_secure = 22.5`\n- `connect_secure = 22.6`\n- `policy_secure = 9.0`\n- `policy_secure = 9.1`\n- `policy_secure = 22.1`\n- `policy_secure = 22.2`\n- `policy_secure = 22.3`\n- `policy_secure = 22.4`\n- `policy_secure = 22.5`\n- `policy_secure = 22.6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":95,"depthScoreParts":{"impact":45.1,"likelihood":20,"exploitation":25,"ransomware":5},"changes":[{"seq":4679,"id":"CVE-2023-46805","ts":1788887199132,"field":"exploit_available","old":"false","new":"true"},{"seq":3562,"id":"CVE-2023-46805","ts":1788886315570,"field":"exploit_available","old":"true","new":"false"},{"seq":2416,"id":"CVE-2023-46805","ts":1788882984397,"field":"exploit_available","old":"false","new":"true"},{"seq":1445,"id":"CVE-2023-46805","ts":1788882397588,"field":"exploit_available","old":"true","new":"false"},{"seq":559,"id":"CVE-2023-46805","ts":1788881833922,"field":"exploit_available","old":"false","new":"true"}]}