FAIL › dossier
Connect Secure and Policy Secure
PRODUCT· dossier confidence 50%
Ivanti Connect Secure and Policy Secure have experienced critical security failures, including zero-day vulnerabilities actively exploited for remote code execution and authentication bypass. These incidents highlight significant weaknesses in the product's security posture and require immediate remediation.
PROFILE
CategorycybersecurityWhat they doIvanti Connect Secure and Policy Secure provide secure remote access solutions. They offer features like VPN, application access, and policy enforcement.
SECURITY POSTURE
Connect Secure and Policy Secure have demonstrated a critical vulnerability track record, with multiple zero-day vulnerabilities exploited in the wild. These vulnerabilities allowed for authentication bypass and arbitrary code execution.
Notable failures
- CVE-2023-46805 Authentication Bypass
- CVE-2024-21887 Command Injection
- Active Exploitation in the Wild
Patterns: Zero-day vulnerabilities; Remote Code Execution (RCE); Authentication Bypass
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-01-10 | CVE-2023-46805 | critical | Ivanti Connect Secure and Policy Secure suffered an authentication bypass vulnerability that allowed attackers to access restricted resources, which could be combined with a command injection flaw for full system compromise. |
| 2024-01-10 | CVE-2024-21887 | critical | Ivanti Connect Secure and Policy Secure suffered a critical command injection vulnerability that was actively exploited in the wild to execute arbitrary code on appliances. |
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-22 04:20:00.109027+00:00