漏洞描述
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
forums.ivanti.comhttps://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2023-46805↗packetstormsecurity.comhttp://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html↗github.comhttps://github.com/H4lo/awesome-IoT-security-article↗github.comhttps://github.com/inguardians/ivanti-VPN-issues-2024-research↗