ThreatPaper

#cve-2023-46805

1 case

CVE-2023-46805 and CVE-2024-21887 gave a suspected China-nexus actor unauthenticated code execution on Ivanti VPN gateways from December 2023. Disclosure turned it into 2,100 compromised appliances in a week, a bypassed mitigation and CISA's order to unplug every federal device.

State-SponsoredMalware