Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
2024-08-13T19:15:16.940
2025-10-24T13:54:52.943
Analyzed
3c1d8aa1-5a33-4ea4-8992-aadd6440af75
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ivanti | virtual_traffic_management | 22.2 | Yes |
| Application | ivanti | virtual_traffic_management | 22.3 | Yes |
| Application | ivanti | virtual_traffic_management | 22.3 | Yes |
| Application | ivanti | virtual_traffic_management | 22.5 | Yes |
| Application | ivanti | virtual_traffic_management | 22.6 | Yes |
| Application | ivanti | virtual_traffic_management | 22.7 | Yes |