First published: Tue Aug 13 2024(Updated: )
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
Credit: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Virtual Traffic Management | =22.2 | |
Ivanti Virtual Traffic Management | =22.3 | |
Ivanti Virtual Traffic Management | =22.3-r2 | |
Ivanti Virtual Traffic Management | =22.5-r1 | |
Ivanti Virtual Traffic Management | =22.6-r1 | |
Ivanti Virtual Traffic Management | =22.7-r1 | |
Ivanti Virtual Traffic Manager |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.