Sources agree
Cure53's November and December 2019 white-box pentest of IVPN's VPN service, internal servers and web servers (21 person-days, 6 testers) found nine issues (3 High, 2 Medium, 3 Low, 1 Info); IVPN says all were resolved, and Cure53 notes it verified the fix on 8 of the 9.
2 separate sources: Cure53 and IVPN
Sources and caveats (2)
The presence of nine issues on the IVPN scope cannot be taken lightly
Counts toward the two-source rule
Conflict of interest: Commissioned and paid for by IVPN; IVPN published a redacted copy (vulnerability details removed)
A total of 9 issues (3 high, 2 medium, 3 low, 1 info) were discovered, all of which were either immediately resolved or have since been resolved.
Counts toward the two-source rule
Researcher notes
The three High issues: IVP-02-005 account takeover through missing CSRF protection (IVPN says the CSRF middleware was commented out and pushed to production by a developer debugging staging); IVP-02-006 vulnerable CRM add-on modules (legacy system reachable only from IVPN's internal network with 2FA); IVP-02-008 SSH-agent use could lead to full network takeover. Also IVP-02-003 'Swap space can lead to unintentional logging' (Info, fixed and verified): a privacy-relevant finding. Cure53 gave a fix note of 'addressed by IVPN and the deployed fix was verified' on 8 of 9; IVP-02-009 (RADIUS weak hashing, Low) carries no fix note. Cure53 also positively rated the VPN topology and OpenVPN configuration. Scope limits stated by IVPN: no access to production VPN servers; a dedicated audit environment replicated production. The published report has vulnerability details removed. IVPN's blog first mis-added the Low count as 1; a comment on the post corrected it to 3 in April 2020.