PT-2023-29834 · Ivanti · Ivanti Connect Secure+1
Qilin_99
·
Published
2023-10-22
·
Updated
2024-09-02
·
CVE-2023-46085
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wpmet Wp Ultimate Review plugin versions 2.2.4 and earlier
ICS versions 9.x and 22.x
IPS (affected versions not specified)
Ivanti Connect Secure and Policy Secure gateways (affected versions not specified)
Description
The issue concerns an authentication bypass vulnerability and a Cross-Site Request Forgery (CSRF) vulnerability. The authentication bypass vulnerability allows a remote attacker to access restricted resources by bypassing control checks. The CSRF vulnerability is present in the Wpmet Wp Ultimate Review plugin. Ivanti has published an advisory detailing two vulnerabilities affecting Connect Secure and Policy Secure gateways, and it is aware that both vulnerabilities are being actively exploited.
Recommendations
For Wpmet Wp Ultimate Review plugin versions 2.2.4 and earlier, update to a version later than 2.2.4 to resolve the CSRF vulnerability.
For ICS versions 9.x and 22.x, apply the necessary patches or updates to address the authentication bypass vulnerability.
For IPS, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Ivanti Connect Secure and Policy Secure gateways, apply the patches or updates provided by Ivanti to address the vulnerabilities.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Connect Secure
Ivanti Policy Secure