CVE-2023-46805
KEV RANSOMWAREHIGH 8.2EPSS 100.0%
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
- CVSS v3.1
- 8.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N - CVSS v3.0
- 8.2 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N - EPSS
- 99.99% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-01-10, used in ransomware campaigns
- Nuclei
- high · CWE-287
- Published
- 2024-01-12
- Updated
- 2026-08-04
Proof-of-concept exploits (9)
- http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-…
- Chocapikk/CVE-2023-4680514★ · 2024-01-19
- cbeek-r7/CVE-2023-468055★ · 2024-01-19
- duy-31/CVE-2023-46805_CVE-2024-2188723★ · 2024-01-17
- raminkarimkhani1996/CVE-2023-46805_CVE-2024-218875★ · 2024-03-23
- rxwx/pulse-meter1★ · 2025-02-13
- stephen-murcott/Ivanti-ICT-Snapshot-decryption1★ · 2024-02-08
- w2xim3/CVE-2023-468052★ · 2024-01-25
- yoryio/CVE-2023-4680510★ · 2024-07-23