Description
The Ivanti Connect Secure and Ivanti Policy Secure Gate have a remote command injection vulnerability. An attacker can bypass the authentication using CVE-2023-46805 and exploit the RCE to compromise the system.
Remediation
Upgrade to the latest version of Ivanti Connect Secure / Policy Secure
References
Related Vulnerabilities
Magento Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-7874)
OpenSSL Cryptographic Issues Vulnerability (CVE-2015-0205)
Oracle JRE CVE-2013-1558 Vulnerability (CVE-2013-1558)
MySQL CVE-2019-2743 Vulnerability (CVE-2019-2743)
Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-1270)