CVE-2023-46805Ivanti Connect Secure authentication bypass
What broke
Ivanti Connect Secure and Policy Secure (the Pulse Secure VPN descendants) failed to authenticate a request that should have required a session. Chained with CVE-2024-21887 (command injection) this became unauthenticated RCE. Public in January 2024, assigned a 2023 ID. CISA KEV. The later SAML SSRF was the door after this pair was patched.
Why it matters
A SSL VPN is the front door of workforce identity. "Authentication bypass on the VPN" is the whole job of the box failing. Chinese and other state actors used the chain. Identity teams who do not own the VPN still own the fallout: every session, every AD bind the appliance held.
What to do
- Confirm the January 2024 Ivanti builds. If you were internet-facing when this dropped, rebuild. Integrity-check tools missed some implants.
- Rotate LDAP/RADIUS credentials the appliance used.
- Hunt with CISA's ICSA and Mandiant's Integrity Checker notes, not only "we patched."
After you patch
Edge appliances sit outside the estate and hold credentials into it, which is why this class keeps producing multi-victim campaigns.
- Revoke all sessions on the appliance, then rotate the directory or LDAP service account it uses for authentication.
- Rotate certificates and any stored integration credentials, since configuration stores on these devices are a routine post-exploitation target.
- Hunt for authenticated sessions with no matching interactive login, and for logins from ASNs that had never appeared before the disclosure date.
- Check downstream: anything the appliance could reach or authenticate to is in scope, including SSO-connected applications.
Sources
- NVD: CVE-2023-46805
- Ivanti KB for CVE-2023-46805 / CVE-2024-21887
- CISA KEV
Related identity CVEs
Related on Start with Identity
- CVEIvanti Sentry authentication bypass
Ivanti Sentry (MobileIron Sentry) skipped authentication on an administrative API. CISA KEV. August 2023. The gateway in front of EPMM had its own unlocked door
- CVEIvanti EPMM (MobileIron Core) unauthenticated API access
Every supported EPMM 11.8-11.10 release exposed restricted API functionality with no login. Attackers pulled user and device data, then chained CVE-2023-35081.
- CVEJetBrains TeamCity 2023 authentication bypass to RCE
Unauthenticated request becomes administrator, then code execution, on TeamCity On-Premises before 2023.05.4. CVSS 9.8. CISA KEV. Used by Russian state actors.
- GlossaryZTNA
Zero Trust Network Access. The product category that replaces VPNs with identity-aware proxies. ZTNA grants access to specific applications based on identity an
- BlogA CVE ID is a name. The value is knowing who the attacker becomes.
We opened a practitioner catalog of identity CVEs: what broke, why IAM teams should care, and what to do this week. Not an NVD mirror. A place to triage SAML wr
- VendorCisco Secure Access
strong_contender