An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
Loading...
Loading...
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2024-01-10), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 8.2 retained for reference. Confidence: HIGH.
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
January 12, 2024
October 31, 2025
Known Exploited Vulnerabilities Catalog | CISA. Listed in CISA Known Exploited Vulnerabilities catalog.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46805MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (1 Metasploit module) (8 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
A Python script for examining Ivanti Secure Connect (ICS) event logs, designed to support investigations into vulnerabilities CVE-2025-0282, CVE-2023-46805, and CVE-2024-21887.
Open source ↗CVE-2023-46805 Ivanti POC RCE - Ultra fast scanner.
Open source ↗Ivanti Pulse Secure CVE-2023-46805 Scanner - Based on Assetnote's Research
Open source ↗Mitigation validation utility for the Ivanti Connect Around attack chain. Runs multiple checks. CVE-2023-46805, CVE-2024-21887.
Open source ↗The script in this repository only checks whether the vulnerabilities specified in the Ivanti Connect Secure product exist.
Open source ↗Simple scanner for scanning a list of ip-addresses for vulnerable Ivanti Pulse Secure devices
Open source ↗An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
Open source ↗Scanner for CVE-2023-46805 - Ivanti Connect Secure
Open source ↗Ivanti Connect Secure Unauthenticated Remote Code Execution
Open source ↗Ivanti ICS - Authentication Bypass
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2023-46805
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
CWE-287