Vulnerability threat dossier

CVE-2023-46805

ivanticonnect secure

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

VTP deterministic threat50.0of 100 · CVSS excluded

VTP analyst assessment

Ivanti Connect Secure authentication bypass

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence96%
Public exploitation · VTP factKEV

Assessment

CISA KEV establishes known global exploitation and known ransomware-campaign use. The web component of Ivanti Connect Secure and Policy Secure permits unauthenticated remote access to restricted resources by bypassing control checks.

Why it matters

  • Affected remote-access appliances expose restricted resources without authentication and may support further compromise.
  • EPSS 0.99986 is extreme predictive context but does not prove VTP observation.

Evidence

1 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The accessible resources and any downstream exploit chain are not described.

No first-party telemetry, public-intelligence assertions, or exploit artifact is supplied.

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

Next watchpoint

Identify affected Connect Secure and Policy Secure versions and verify remediation.

AI baseline history (1)
  1. BASELINE ASSESSED
    Ivanti Connect Secure authentication bypassgpt-5.6-sol · high
Technical severityHIGHCVSS 8.2 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Availability: SENSOR_ONLINE_ACTIVITY_OBSERVED · Evidence: CVE_LIKE_ATTEMPT
HIGH

Honeypot request semantics are strongly consistent with CVE-2023-46805. This identifies likely attack intent, not successful exploitation or execution.

STRONGLY COMPATIBLETechnical consistency 95/100

Basis: deterministic technical candidate

Strongly consistent attempt; successful exploitation not observedDisclosure embargo completed
HIGH

Honeypot request semantics are strongly consistent with CVE-2023-46805. This identifies likely attack intent, not successful exploitation or execution.

STRONGLY COMPATIBLETechnical consistency 95/100

Basis: deterministic technical candidate

Strongly consistent attempt; successful exploitation not observedDisclosure embargo completed
LOW

The request shares exploitation-associated characteristics with CVE-2023-46805, but the evidence does not identify one CVE with sufficient confidence.

CANDIDATE LEADTechnical consistency 35/100

Basis: deterministic technical candidate

Potentially consistent; exploitation not confirmedDisclosure embargo completed
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  3. 03

    Exploitation attempts against this CVE were confirmed by first-party telemetry.

  4. 04

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

0publications detected
0underlying evidence chains

0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

  1. 00:0010 Jan
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

06

Technical vulnerability data

Context, not threat proof

VTP threat score50.0vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction20 / 20
Exploit availability0 / 15
Source independence0 / 15
Intelligence recency0 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
8.2 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CWE
CWE-287
CPE records
81
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.