Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ivanti Virtual Traffic Manager | — | Upgrade Ivanti Virtual Traffic Manager to the latest version | Oct 3, 2025 | Aug 12, 2024 |
| Pulse Secure Pulse Connect Secure | — | Update Ivanti Connect Secure to version 22.5R2Update Ivanti Connect Secure to version 22.2R1Update Ivanti Connect Secure to version 22.7R2Update Ivanti Connect Secure to version 22.6R2Update Ivanti Connect Secure to version 22.3R3 | Mar 26, 2026 | Aug 12, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub