Authentication bypass vulnerability in Ivanti Virtual Traffic Manager

ISGroup Cybersecurity

Executive Summary

A critical vulnerability in the Ivanti Virtual Traffic Manager system allows unauthenticated remote attackers to create administrative accounts. The issue affects versions prior to 22.2R1 and 22.7R2. Ivanti has released corrective patches, and a public proof-of-concept is also available. Given the history of exploits involving Ivanti products, particularly those related to similar authentication bypass issues, it is critical to apply the fixes immediately or implement mitigation measures.

ProductIvanti vTM
Date2024-09-09 09:54:40

Technical Summary

Ivanti’s Virtual Traffic Manager (vTM) contains a critical authentication bypass flaw that allows unauthenticated remote attackers to create users with administrative privileges. Versions prior to 22.2R1 and 22.7R2 are affected. Ivanti has released patches, and a public proof-of-concept is available. The history of exploits against Ivanti products, including previous authentication bypass vulnerabilities, highlights the urgency of applying patches or mitigation measures immediately.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert