Junglewise Threat Intelligence

CVE-2024-7593: Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

CVE-2024-7593 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-09-24

Vendors: Ivanti.

Executive brief

An incorrect implementation of an authentication algorithm in Ivanti Virtual Traffic Manager (vTM) allows a remote, unauthenticated attacker to bypass the admin panel authentication. This vulnerability enables the creation of a chosen administrator account, granting full control over the affected system.

Affected products

  • Ivanti Virtual Traffic Manager (vTM) Versions other than 22.2R1 or 22.7R2

Timeline

  • 2024-08-13: disclosed: Initial NVD publication date
  • 2024-09-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-09-24: advisory: Updated advisory publication date
  • 2024-10-15: other: CISA KEV remediation due date

Related threats