Executive brief
An incorrect implementation of an authentication algorithm in Ivanti Virtual Traffic Manager (vTM) allows a remote, unauthenticated attacker to bypass the admin panel authentication. This vulnerability enables the creation of a chosen administrator account, granting full control over the affected system.
Affected products
- Ivanti Virtual Traffic Manager (vTM) Versions other than 22.2R1 or 22.7R2
Timeline
- 2024-08-13: disclosed: Initial NVD publication date
- 2024-09-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-09-24: advisory: Updated advisory publication date
- 2024-10-15: other: CISA KEV remediation due date