>> All posts

Exposed Ivanti Connect Secure VPN logins and password spraying

The short version: An internet-facing Ivanti Connect Secure VPN login is, by design, a gateway into your internal network — and attackers spray common and breached passwords against these portals constantly, because one working credential lands them inside.

What you need to know

There's no CVE here — this is about the exposed VPN login and the credentials behind it. Ivanti Connect Secure (formerly Pulse Connect Secure) is a remote-access VPN whose whole purpose is to let authenticated users reach internal resources. That makes its login a uniquely valuable target: success isn't access to one app, it's a standing position inside the network.

  • How they find it — crawling surfaces the recognizable Ivanti/Pulse Secure VPN login (dana-na) on an internet-facing host.
  • How they use it — automated, low-and-slow spraying with common and previously-breached passwords, staying under lockout thresholds.
  • What it leads to — a valid credential grants VPN access into the internal network, sensitive data, and room to expand from a trusted position.

How serious we see it

High. A VPN login is not an ordinary web form — it's the front door to the internal network, and these appliances are among the most heavily targeted on the internet. Where MFA is enforced and passwords are strong and unique, the exposure is contained. But a weak or reused credential without MFA is a direct, unauthenticated-to-internal path, which is why we rate it above a typical exposed login. The steady note: it's fixable today, and confirming whether it applies to you is quick.

What to do

  • Enforce MFA on every VPN account — the single highest-value control; it defeats spraying even when a password is known.
  • Kill weak and reused passwords — enforce strong, unique credentials and check them against known-breached lists.
  • Limit and monitor failed authentication — rate-limit attempts and alert on spray patterns (many accounts, few passwords, low-and-slow).
  • Keep the appliance current — VPN appliances are frequent exploitation targets, so pair strong auth with prompt patching.
  • Confirm your exposure first — verify whether any Ivanti Connect Secure VPN login is reachable from the internet today.

How BreachRisk sees it

BreachRisk discovers exposed Ivanti Connect Secure VPN logins the way an attacker would — by crawling your external footprint — and then, where authorized, goes a step further than a scanner: it safely attempts a bounded, rate-limited authentication check using exposed (breach-corpus) and common credentials, within strict non-disruptive limits rather than a brute-force flood. That's the honest difference between detecting the VPN login and demonstrating whether it actually holds.

References

See your cyber risk, proven.