CVE-2023-46805
HIGH KEV RANSOMWARE NUCLEIIvanti Connect Secure Unauthenticated Remote Code Execution
Title source: metasploitDescription
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
Exploits (13)
nomisec
WORKING POC
23 stars
by duy-31 · remote
https://github.com/duy-31/CVE-2023-46805_CVE-2024-21887
nomisec
SCANNER
12 stars
by seajaysec · infoleak
https://github.com/seajaysec/Ivanti-Connect-Around-Scan
nomisec
WORKING POC
5 stars
by Hexastrike · poc
https://github.com/Hexastrike/Ivanti-Connect-Secure-Logs-Parser
nomisec
WORKING POC
5 stars
by raminkarimkhani1996 · infoleak
https://github.com/raminkarimkhani1996/CVE-2023-46805_CVE-2024-21887
metasploit
WORKING POC
EXCELLENT
by sfewer-r7 · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ivanti_connect_secure_rce_cve_2023_46805.rb
metasploit
WORKING POC
EXCELLENT
by sfewer-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ivanti_connect_secure_rce_cve_2024_21893.rb
Nuclei Templates (1)
Ivanti ICS - Authentication Bypass
HIGHby DhiyaneshDK,daffainfo,geeknik
Shodan:
html:"welcome.cgi?p=logo"
FOFA:
body="welcome.cgi?p=logo"
References (3)
Scores
CVSS v3
8.2
EPSS
0.9437
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Details
CISA KEV
2024-01-10
VulnCheck KEV
2024-01-10
InTheWild.io
2024-01-10
ENISA EUVD
EUVD-2023-50971
Ransomware Use
Confirmed
CWE
CWE-287
Status
published
Products (10)
ivanti/connect_secure
9.0
ivanti/connect_secure
9.1 r1 (32 CPE variants)
ivanti/connect_secure
22.1 r1 (2 CPE variants)
ivanti/connect_secure
22.2 (2 CPE variants)
ivanti/connect_secure
22.3 r1
ivanti/connect_secure
22.4 r1 (2 CPE variants)
ivanti/connect_secure
22.5 r2.1
ivanti/connect_secure
22.6 (3 CPE variants)
ivanti/policy_secure
9.0
ivanti/policy_secure
9.1 r1 (5 CPE variants)
Published
Jan 12, 2024
KEV Added
Jan 10, 2024
Tracked Since
Feb 18, 2026