Breaking API Auth — How to Find, Fix,

Exploiting Critical API Authentication
Exploiting Critical API Authentication represents a severe threat, allowing unauthorized access to sensitive systems. One notable instance is CVE-2023-46805, an authentication bypass vulnerability affecting Ivanti Connect Secure (ICS) and Ivanti Policy Secure gateways. This flaw enables remote attackers to access restricted resources by circumventing control checks. When chained with other vulnerabilities, such as CVE-2024-21887 (command injection), it can lead to unauthenticated remote code execution, granting threat actors a direct path into an organization's internal network.
Vulnerability and Impact
CVE-2023-46805 is an authentication bypass vulnerability in the web component of Ivanti Connect Secure and Ivanti Policy Secure gateways. It holds a CVSS v3.1 Base Score of 8.2 (High severity), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N. This score reflects the critical nature of the flaw: an attacker can exploit it over the network without any privileges or user interaction. The vulnerability primarily impacts the confidentiality and integrity of the system.
Affected versions include all supported versions of Ivanti Connect Secure 9.x and 22.x, as well as Ivanti Policy Secure. Ivanti Neurons for ZTA gateways are not directly vulnerable when in production, but generated gateways left unconnected to a ZTA controller are at risk. The compromise of these VPN gateways provides a direct path into an organization's internal resources, making the impact severe. Successful exploitation can lead to data exfiltration, ransomware deployment, and espionage.
Technical Root Cause Analysis
The root cause of CVE-2023-46805 lies in improper validation of authentication tokens within the application's web component. Specifically, it is a path traversal vulnerability found in the "/api/v1/totp/user-backup-code" endpoint. This endpoint does not require authentication, allowing adversaries to access public-facing endpoints. Attackers can manipulate certain URI paths to access restricted endpoints, bypassing authentication checks. This flaw does not grant code execution on its own, but it provides unauthenticated access to the internal workings of the VPN gateway.
The vulnerability essentially allows an attacker to sidestep access controls and gain entry into protected parts of the VPN gateway without valid credentials. The application's web component fails to adequately verify requests, permitting specially crafted URIs to bypass normal authentication flows. This design oversight creates a critical gap, enabling unauthorized access that sets the stage for further compromise.
Exploitation Mechanics
Exploiting Critical API Authentication via CVE-2023-46805 involves sending a specially crafted HTTP request to the vulnerable Ivanti appliance. An attacker manipulates the URI to traverse directories and access endpoints that should typically require authentication. The "/api/v1/totp/user-backup-code" endpoint is key here, as it lacks proper authentication checks. By appending path traversal sequences (e.g., `../../`) to this unauthenticated endpoint, an attacker can reach protected resources.
For example, an attacker could craft a GET request like this:
GET /api/v1/totp/user-backup-code/../../license/keys-status/ HTTP/1.1
Host: [VULNERABLE_IVANTI_HOST]
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
Accept: /
Accept-Encoding: gzip, deflate
Connection: close
This request, without any authentication headers, can retrieve sensitive license status information, which would normally be restricted. While CVE-2023-46805 itself only provides authentication bypass, it is almost always chained with a command injection flaw like CVE-2024-21887. This combination allows an unauthenticated attacker to execute arbitrary commands on the system. The initial bypass grants access, and the command injection then provides remote code execution capability.
Detection: How to Check if You're Affected
Organizations must proactively detect signs of CVE-2023-46805 exploitation. First, verify if your Ivanti Connect Secure or Policy Secure gateways run vulnerable versions (9.x or 22.x). Ivanti provides an External Integrity Checker Tool (ICT) to scan for compromise, including modified files or unauthorized processes. It is crucial to run the external ICT, as threat actors have attempted to manipulate the internal one.
Network traffic analysis tools are essential. Look for unusual log entries related to authentication, excessive unauthorized access attempts, and requests with suspiciously malformed tokens. Specifically, monitor for unauthenticated requests to restricted API endpoints like `/api/v1/totp/user-backup-code/` followed by path traversal sequences. Security Information and Event Management (SIEM) solutions can correlate these events, flagging potential exploitation.
Utilize an Secably free website vulnerability scanner to identify exposed Ivanti instances and detect known vulnerabilities. Our free port scanner can help identify publicly accessible services. For broader reconnaissance and to find exposed services across your attack surface, tools like Zondex provide internet-wide scanning capabilities. These tools help identify external-facing instances of impacted applications through attack surface rules.
Remediation Steps
Immediate patching is the top priority for CVE-2023-46805. Ivanti has released updates for all affected versions of Connect Secure and Policy Secure. Apply these patches without delay. Ivanti recommends running the External Integrity Checker Tool before patching to detect any existing compromise. If the tool indicates compromise, you are in an incident response scenario and should proceed with recovery steps.
Ivanti's recovery guidance includes factory resetting the appliance to return it to a known-good state, then upgrading to a patched version. Do not rejoin a recovered appliance to the previous cluster; instead, run it as a standalone unit initially. Implement additional access controls, such as multi-factor authentication, and review currently logged-in sessions, terminating any suspicious ones. Restrict access to Ivanti products to essential personnel only. For detailed instructions and ongoing updates, consult Ivanti's official security advisories and knowledge base articles, such as KB CVE-2023-46805.
Timeline of Disclosure
- January 10, 2024: Ivanti publicly disclosed CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection) via a security advisory. Volexity reported active exploitation as zero-day vulnerabilities.
- January 11, 2024: Broader exploitation began, likely related to pre-notification activity. CISA added both CVEs to their Known Exploited Vulnerability Catalog.
- January 12, 2024: CVE-2023-46805 was published to the NVD.
- January 16, 2024: A public Proof of Concept (PoC) for the exploit chain was released by a third party. Intense scanning for the vulnerability commenced.
- January 19, 2024: CISA issued an emergency directive regarding the vulnerabilities.
- January 22, 2024 - February 19, 2024: Ivanti scheduled a staggered release of patches for affected versions.
- January 31, 2024: Ivanti identified and disclosed additional vulnerabilities, CVE-2024-21888 (privilege escalation) and CVE-2024-21893 (server-side request forgery), which are also remediated by the patches.
- February 8, 2024: Ivanti released an advisory about CVE-2024-22024, another authentication bypass vulnerability.
- February 29, 2024: CISA, along with international partners, released a joint Cybersecurity Advisory warning of active exploitation and the ability of threat actors to deceive Ivanti's internal and previous external Integrity Checker Tools.
Check your site for vulnerabilities
Run a free security scan — no signup, results in seconds.