CVE-2024-7593
Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 October 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.99% probability · 100th percentile
- CISA KEV
- Listed 24 September 2024 · due 15 October 2024
- Weakness
- CWE-287, CWE-303
- Affected
- ivanti/virtual traffic manager
- Source
- 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593 ; https://nvd.nist.gov/vuln/detail/CVE-2024-7593
References
- https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593Mitigation, Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7593US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.