← לוח פגיעויות

CVE-2023-46805

גבוהה 8.2 מנוצלת בשטח (KEV) בשימוש בכופרה

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

מדדים

CVSS 3.1
8.2 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
EPSS — סבירות ניצול
100% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-287

מוצרים מושפעים

ivanti: connect secure; ivanti: policy secure

קישורים