EXPOSURES › CVE-2023-46805
CVE-2023-46805
CRITICAL ⌖ ON CISA KEV · EXPLOITEDIvanti Connect Secure and Policy Secure suffered an authentication bypass vulnerability that allowed attackers to access restricted resources, which could be combined with a command injection flaw for full system compromise.
The authentication bypass in Ivanti's web component let attackers bypass control checks to access restricted resources, and when paired with CVE-2024-21887, enabled command injection. DIB organizations must patch these gateways immediately to prevent lateral movement and data exfiltration, as this pattern mirrors other Ivanti failures in 2025-2026.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching and secure design.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |