# Ivanti Connect Secure authentication bypass

Source: https://startwithidentity.com/cves/cve-2023-46805/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

Ivanti Connect Secure and Policy Secure (the Pulse Secure VPN descendants) failed to authenticate a request that should have required a session. Chained with CVE-2024-21887 (command injection) this became unauthenticated RCE. Public in January 2024, assigned a 2023 ID. CISA KEV. The later [SAML SSRF](https://startwithidentity.com/cves/cve-2024-21893/) was the door after this pair was patched.

## Why it matters

A SSL VPN is the front door of workforce identity. "Authentication bypass on the VPN" is the whole job of the box failing. Chinese and other state actors used the chain. Identity teams who do not own the VPN still own the fallout: every session, every AD bind the appliance held.

## What to do

- Confirm the January 2024 Ivanti builds. If you were internet-facing when this dropped, rebuild. Integrity-check tools missed some implants.
- Rotate LDAP/RADIUS credentials the appliance used.
- Hunt with CISA's ICSA and Mandiant's Integrity Checker notes, not only "we patched."

## After you patch

Edge appliances sit outside the estate and hold credentials into it, which is why this class keeps producing multi-victim campaigns.

- **Revoke all sessions on the appliance**, then rotate the directory or [LDAP](https://startwithidentity.com/glossary/federation/) service account it uses for authentication.
- **Rotate certificates and any stored integration credentials**, since configuration stores on these devices are a routine post-exploitation target.
- **Hunt for authenticated sessions with no matching interactive login**, and for logins from ASNs that had never appeared before the disclosure date.
- **Check downstream**: anything the appliance could reach or authenticate to is in scope, including [SSO](https://startwithidentity.com/glossary/sso/)-connected applications.

## Sources

- [NVD: CVE-2023-46805](https://nvd.nist.gov/vuln/detail/CVE-2023-46805)
- Ivanti KB for CVE-2023-46805 / CVE-2024-21887
- CISA KEV
