Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Virtual_traffic_management | Ivanti | 22.2 (including) | 22.2 (including) |
Virtual_traffic_management | Ivanti | 22.3 (including) | 22.3 (including) |
Virtual_traffic_management | Ivanti | 22.3-r2 (including) | 22.3-r2 (including) |
Virtual_traffic_management | Ivanti | 22.5-r1 (including) | 22.5-r1 (including) |
Virtual_traffic_management | Ivanti | 22.6-r1 (including) | 22.6-r1 (including) |
Virtual_traffic_management | Ivanti | 22.7-r1 (including) | 22.7-r1 (including) |