CVE-2023-46805High· 8.2▾ Abyssal⚠ Exploited in the wild0dayPoC availableAn authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 45.1 · likelihood 20 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Federal remediation due Jan 22, 2024
Disclosed via NVD
Last analysed / modified upstream
100%
9 GitHub repos · Metasploit ×1 · Nuclei ×1
Added to the CISA catalog on Jan 10, 2024. Federal remediation due Jan 22, 2024. View catalog ↗
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
connect_secure = 9.0connect_secure = 9.1connect_secure = 22.1connect_secure = 22.2connect_secure = 22.3connect_secure = 22.4connect_secure = 22.5connect_secure = 22.6policy_secure = 9.0policy_secure = 9.1policy_secure = 22.1policy_secure = 22.2policy_secure = 22.3policy_secure = 22.4policy_secure = 22.5policy_secure = 22.6Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-21887Critical· 9.1A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…
CVE-2021-22893Critical· 10.0Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticat…
CVE-2023-35078Critical· 9.8An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
CVE-2025-22457Critical· 9.0A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code…
CVE-2025-0282Critical· 9.0A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve…
CVE-2024-21893High· 8.2A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…