CVE-2023-46805: Ivanti Connect Secure Auth Bypass
An authentication bypass vulnerability in Ivanti Connect Secure and Ivanti Policy Secure gateways, affecting specific web component URIs that fail to enforce authentication. Exploited in the wild as a zero-day starting in late 2023, it lets an unauthenticated attacker access restricted resources, and when chained with a separate command injection flaw (CVE-2024-21887), enables full unauthenticated remote code execution.
View the authoritative record on NVD ↗Affected software
- Ivanti Connect Secure (9.x and 22.x)
- Ivanti Policy Secure gateways, versions prior to the January 2024 patches
How it's exploited
Send a crafted HTTP request to specific web component URIs that lack proper authentication enforcement, gaining unauthorized access to restricted appliance resources; chained with the command injection flaw tracked as CVE-2024-21887, this becomes unauthenticated remote code execution on the gateway.
Severity
CVE-2023-46805 carries a CVSS 3.1 base score of 8.2, rated High. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2023-46805 is categorized under CWE-287, the general weakness pattern behind this specific vulnerability.
How TurboPentest tests for this
TurboPentest tests authentication dynamically, following the OWASP testing guides across login, session, and multi-factor flows to find bypasses and weak credential handling. Paladin AI chains findings across requests to surface multi-step authentication weaknesses. A manual IntegSec engagement applies deeper methodology.
Tools: Paladin AI, OWASP ZAP
Remediation
Apply Ivanti's mitigation and the subsequent official patches addressing both CVE-2023-46805 and CVE-2024-21887, and follow Ivanti and CISA's guidance to check for prior compromise, since this pair was actively exploited as a zero-day before fixes existed.
Frequently asked questions
What is CVE-2023-46805?
An authentication bypass vulnerability in Ivanti Connect Secure and Ivanti Policy Secure gateways, affecting specific web component URIs that fail to enforce authentication. Exploited in the wild as a zero-day starting in late 2023, it lets an unauthenticated attacker access restricted resources, and when chained with a separate command injection flaw (CVE-2024-21887), enables full unauthenticated remote code execution.
How severe is CVE-2023-46805?
CVE-2023-46805 has a CVSS 3.1 base score of 8.2 out of 10, rated High.
What software is affected by CVE-2023-46805?
CVE-2023-46805 affects Ivanti Connect Secure (9.x and 22.x); Ivanti Policy Secure gateways, versions prior to the January 2024 patches.
How do you fix CVE-2023-46805?
Apply Ivanti's mitigation and the subsequent official patches addressing both CVE-2023-46805 and CVE-2024-21887, and follow Ivanti and CISA's guidance to check for prior compromise, since this pair was actively exploited as a zero-day before fixes existed.
Where is the authoritative record for CVE-2023-46805?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2023-46805 at https://nvd.nist.gov/vuln/detail/CVE-2023-46805, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest