Identity CVE · Other
CVE-2023-46805Ivanti Connect Secure authentication bypass
criticalCISA KEVActively exploited
Product: Ivanti Connect Secure / Policy SecureVendor: IvantiCWE-287Disclosed: 2024-01-10Status: Actively exploitedNVD ↗CISA KEV ↗
What broke
Ivanti Connect Secure and Policy Secure (the Pulse Secure VPN descendants) failed to authenticate a request that should have required a session. Chained with CVE-2024-21887 (command injection) this became unauthenticated RCE. Public in January 2024, assigned a 2023 ID. CISA KEV. The later SAML SSRF was the door after this pair was patched.
Why it matters
A SSL VPN is the front door of workforce identity. "Authentication bypass on the VPN" is the whole job of the box failing. Chinese and other state actors used the chain. Identity teams who do not own the VPN still own the fallout: every session, every AD bind the appliance held.
What to do
- Confirm the January 2024 Ivanti builds. If you were internet-facing when this dropped, rebuild. Integrity-check tools missed some implants.
- Rotate LDAP/RADIUS credentials the appliance used.
- Hunt with CISA's ICSA and Mandiant's Integrity Checker notes, not only "we patched."
Sources
- NVD: CVE-2023-46805
- Ivanti KB for CVE-2023-46805 / CVE-2024-21887
- CISA KEV
Related identity CVEs
Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.