An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence96%
Public exploitation · VTP factKEV
Assessment
CISA KEV establishes known global exploitation and known ransomware-campaign use. The web component of Ivanti Connect Secure and Policy Secure permits unauthenticated remote access to restricted resources by bypassing control checks.
Why it matters
Affected remote-access appliances expose restricted resources without authentication and may support further compromise.
EPSS 0.99986 is extreme predictive context but does not prove VTP observation.
Evidence
1 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
The accessible resources and any downstream exploit chain are not described.
No first-party telemetry, public-intelligence assertions, or exploit artifact is supplied.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
Identify affected Connect Secure and Policy Secure versions and verify remediation.
AI baseline history (1)
BASELINE ASSESSED
Ivanti Connect Secure authentication bypassgpt-5.6-sol · high
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Honeypot request semantics are strongly consistent with CVE-2023-46805. This identifies likely attack intent, not successful exploitation or execution.
Honeypot request semantics are strongly consistent with CVE-2023-46805. This identifies likely attack intent, not successful exploitation or execution.
CISA KEV lists this vulnerability as known to be exploited globally.
02
EPSS is 1.00; this is predictive context, not exploitation evidence.
03
Exploitation attempts against this CVE were confirmed by first-party telemetry.
04
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
KEV ADDEDCISA KEV entry added
03
Claim provenance
Evidence and source independence
0publications detected
0underlying evidence chains
0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
04
Event history
Threat timeline
00:0010 Jan
KEV ADDED
CISA KEV entry added
CISA lists global known exploitation. This is not a VTP sensor observation.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.