LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-46805: Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 10, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jan 22, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-46805 to its Known Exploited Vulnerabilities catalog on Jan 10, 2024, with a federal patch deadline of Jan 22, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to…

CVE-2023-46805 is an authentication bypass vulnerability affecting Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure gateways. It allows an unauthenticated attacker to reach restricted resources on the web component by bypassing control checks. The flaw matters because these products commonly sit at the network edge as VPN and access gateways; successful abuse can give attackers a foothold that has been chained with a separate command-injection issue (CVE-2024-21887) and has been used in ransomware campaigns. Confirm exact impact and fixed releases against the vendor advisory.

How it works

The weakness is classified as CWE-287 (Improper Authentication). In the web component of the affected gateways, authentication and authorization checks can be bypassed, letting an attacker obtain access to resources that should require valid credentials or session state. Public detail on the precise request path or parameter is limited; defenders should treat any unauthenticated request that reaches restricted administrative or API endpoints as potentially abusive. Once the bypass is achieved, the same session or context can be used to trigger further flaws such as the command-injection vulnerability CVE-2024-21887, enabling code execution on the appliance. No exploit code or step-by-step mechanics are provided here; always validate behavior against the official vendor write-up.

Am I affected? How to find it in your systems

Ivanti Connect Secure and Policy Secure typically run as physical or virtual appliances that terminate remote-access VPN, SSL VPN, or policy-enforcement traffic. They appear in network inventories as edge devices, often with public-facing HTTPS listeners and management interfaces. To locate them:

If the product is present and the version or configuration matches the advisory, treat the system as affected until proven otherwise.

How to remediate

The primary action is to apply the vendor-supplied update or mitigation package for CVE-2023-46805 as soon as it is available and tested in your environment. CISA directs organizations to follow the vendor’s instructions or to discontinue use of the product if mitigations cannot be applied. After patching:

Document the change and schedule a follow-up scan to confirm the vulnerability is no longer reported.

If you can't patch immediately

Until the official update can be installed, reduce exposure with compensating controls:

If your data may have been exposed

This vulnerability has been actively exploited and is known to have been used in ransomware operations. If your Ivanti gateways were internet-facing and unpatched during the period of known exploitation, assume possible compromise of credentials, session data, or internal network access. Conduct a full incident-response review, rotate secrets, and examine logs for post-exploitation activity. Separately, individuals can run a free exposure scan of their email addresses against known breach data sets to determine whether personal credentials have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Connect Secure and Policy Secure
WeaknessCWE-287
Added to CISA KEVJan 10, 2024
Federal patch deadlineJan 22, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities