An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
References
Configurations
Configuration 1 (hide)
|
History
31 Oct 2025, 21:59
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46805 - US Government Resource |
21 Oct 2025, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2024-01-12 17:15
Updated : 2025-10-31 21:59
NVD link : CVE-2023-46805
Mitre link : CVE-2023-46805
CVE.ORG link : CVE-2023-46805
JSON object : View
Products Affected
ivanti
- policy_secure
- connect_secure
CWE
CWE-287
Improper Authentication
