PT-2023-8266 · Ivanti · Ivanti Policy Secure+1

CVE-2023-46805

·

Published

2023-01-12

·

Updated

2026-08-04

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ivanti ICS versions 9.x Ivanti ICS versions 22.x Ivanti Policy Secure (affected versions not specified) Ivanti Neurons for Zero Trust Access (affected versions not specified)
Description An authentication bypass exists in the web component of the software, allowing a remote attacker to access restricted resources by bypassing control checks. This may enable an unauthenticated attacker to escalate privileges. Additionally, the software is affected by improper restriction of XML external entity references, which could allow unauthorized access to protected information. Another issue involves the failure to neutralize special elements used in OS commands, potentially allowing a remote attacker to execute arbitrary commands via specially crafted requests. There are reports of these issues being exploited in the real world by suspected nation-state actors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XXE

Improper Authentication

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00249
BDU:2024-00320
BDU:2024-01287
CVE-2023-46805

Affected Products

Ivanti Connect Secure
Ivanti Policy Secure