← Browse

CVE-2023-46805

Act now ● On CISA KEV — actively exploited used in ransomware

Actively exploited — on the CISA KEV list.

CVSS base
8.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
EPSS — probability of exploitation (30 days)
100.0%
100.0th percentile
CISA KEV
Listed
Added 2024-01-10 · patch by 2024-01-22
Weakness / dates
CWE-287
Published 2024-01-12 · modified 2026-08-04

Description

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

Affected

ivanti

References

Official: NVD · CVE.org