logo

Critical Ivanti vTM Bug Allows Unauthorized Admin Access

ID: 2d949672-7a81-5868-806e-392919238721

STIX ID: report--2d949672-7a81-5868-806e-392919238721

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-08-13

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Ivanti patched a critical authentication-bypass vulnerability (CVE-2024-7593) in Virtual Traffic Manager (vTM) that could allow remote, unauthenticated attackers to reach the admin panel and create administrator accounts; a proof-of-concept exploit is publicly available though Ivanti reports no observed customer exploitation. Patched vTM versions and configuration mitigations (restricting management interface exposure) are provided and recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.