Improper Authentication in Ivanti Policy Secure (formerly Pulse Policy Secure) and Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2023-46805
Published: January 10, 2024 / Updated: August 30, 2025
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when processing authentication requests. A remote attacker can bypass authentication process and gain unauthorized access to the application.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Ivanti Connect Secure (formerly Pulse Connect Secure)
How to mitigate CVE-2023-46805
Links to Public Exploits and PoC-codes
- Exploit #11911 - CVE-2023-46805 (Simple scanner for scanning a list of ip-addresses for vulnerable Ivanti Pulse Secure devices) (August 30, 2025)
- Exploit #10074 - CVE-2023-46805_CVE-2024-21887 (An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.) (June 21, 2024)
- Exploit #9839 - CVE-2023-46805_CVE-2024-21887_scan_grouped (May 23, 2024)
- Exploit #9798 - CVE-2023-46805_CVE-2024-21887 (The script in this repository only checks whether the vulnerabilities specified in the Ivanti Connect Secure product exist.) (May 13, 2024)
- Exploit #9517 - Ivanti Connect Secure Unauthenticated Remote Code Execution (January 19, 2024)
External References
- https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US
- https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US