Exposed Ivanti Connect Secure admin portals and password spraying
The short version: An internet-facing Ivanti Connect Secure administrator portal fronts control of the VPN gateway itself — and attackers spray common and breached passwords against these appliances constantly, because one working admin credential is a foothold at the network edge.
What you need to know
There's no CVE here — this is about the exposed admin login and the credentials behind it. Ivanti Connect Secure (formerly Pulse Connect Secure) is a remote-access VPN appliance that sits at the boundary of the internal network. Its administrator portal governs the gateway's configuration, so it's a prized target, and these appliances are heavily probed and sprayed in the wild.
- How they find it — crawling surfaces the recognizable Ivanti/Pulse Secure admin login (
dana-na, admin URLs) on an internet-facing host. - How they use it — automated, low-and-slow spraying with common and previously-breached passwords, staying under lockout thresholds.
- What it leads to — a valid admin credential can mean control of the VPN gateway, a pivot into the internal network, and the ability to expand access from a trusted position.
How serious we see it
High. This is more than an ordinary login: it's the administrative console of an internet-facing access appliance, the kind of target attackers prioritize precisely because a win reaches beyond one host into the internal network. Where MFA is enforced and credentials are strong and unique, the exposure is contained — but a weak or reused admin password here is a direct, high-value path inward. The steady note: it's fixable today, and confirming whether it applies to you is quick.
What to do
- Restrict the admin portal to trusted sources — administration of an edge appliance should not be reachable from the open internet.
- Enforce MFA on every administrator account — the single highest-value control against spraying.
- Kill weak and reused passwords — enforce strong, unique credentials and check them against known-breached lists.
- Limit and monitor failed authentication — rate-limit attempts and alert on spray patterns.
- Confirm your exposure first — verify whether any Ivanti Connect Secure admin portal is reachable from the internet today.
How BreachRisk sees it
BreachRisk discovers exposed Ivanti Connect Secure admin portals the way an attacker would — by crawling your external footprint — and then, where authorized, goes a step further than a scanner: it safely attempts a bounded, rate-limited authentication check using exposed (breach-corpus) and common credentials, within strict non-disruptive limits rather than a brute-force flood. That's the honest difference between detecting the admin login and demonstrating whether it actually holds.