Description
The Ivanti Connect Secure and Ivanti Policy Secure Gate have a remote command injection vulnerability. An attacker can bypass the authentication using CVE-2023-46805 and exploit the RCE to compromise the system.
Remediation
Upgrade to the latest version of Ivanti Connect Secure / Policy Secure
References
Related Vulnerabilities
Oracle HTTP Server Out-of-bounds Read Vulnerability (CVE-2021-4183)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1509)
Oracle JRE CVE-2017-10274 Vulnerability (CVE-2017-10274)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2022-23307)
Apache Tomcat Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2020-13935)