PT-2023-8266 · Ivanti · Ivanti Policy Secure+1
CVE-2023-46805
·
Published
2023-01-12
·
Updated
2026-08-04
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ivanti ICS versions 9.x
Ivanti ICS versions 22.x
Ivanti Policy Secure (affected versions not specified)
Ivanti Neurons for Zero Trust Access (affected versions not specified)
Description
An authentication bypass exists in the web component of the software, allowing a remote attacker to access restricted resources by bypassing control checks. This may enable an unauthenticated attacker to escalate privileges. Additionally, the software is affected by improper restriction of XML external entity references, which could allow unauthorized access to protected information. Another issue involves the failure to neutralize special elements used in OS commands, potentially allowing a remote attacker to execute arbitrary commands via specially crafted requests. There are reports of these issues being exploited in the real world by suspected nation-state actors.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XXE
Improper Authentication
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ivanti Connect Secure
Ivanti Policy Secure