QID 150785

Date Published: 2024-02-08

QID 150785: Ivanti Connect Secure (ICS) and Ivanti Policy Secure Gateways Authentication Bypass Vulnerability (CVE-2023-46805)

Ivanti Connect Secure (ICS) formerly known as Pulse Connect Secure, is a Remote Access VPN solution, and Ivanti Policy Secure is a Network Access Control (NAC) solution developed by Ivanti.

An authentication bypass vulnerability exists in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure which allows a remote attacker to access restricted resources by bypassing control checks.

Affected versions:
Ivanti Connect Secure (ICS) and Ivanti Policy Secure versions 9.x and 22.x

QID Detection Logic (Unauthenticated):
This QID sends HTTP requests to multiple affected endpoints and based on the response determines if the target application is vulnerable.

Successful exploitation of this vulnerability could allow a remote attacker to access restricted resources by bypassing control checks.

  • CVSS V3 rated as Critical - 8.2 severity.
  • CVSS V2 rated as Critical - 8.5 severity.
  • Solution
    Customers are advised to refer Ivanti KB for information pertaining to remediating this vulnerability.

    CVEs related to QID 150785

    Software Advisories
    Advisory ID Software Component Link
    Ivanti URL Logo forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US