Summary

Acunetix 360 detected Authentication Bypass vulnerability.

The Ivanti Connect Secure and Ivanti Policy Secure have an authentication bypass vulnerability.
An attacker can bypass the authentication with a specially crafted HTTP request
and get administrative access to the system.

Impact

An unauthenticated attacker can compromise the Ivanti Connect Secure / Policy Secure.

Remediation

Upgrade to the latest version of Ivanti Connect Secure / Policy Secure

Severity

High

Classification

PCI v3.2-6.5.1 CAPEC-114,115 CWE-287 HIPAA-164.306(a) ISO27001-A.13.1.1 WASC-1 OWASP 2013-A9 OWASP 2017-A9 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N