Critical Ivanti vTM Bug Allows Unauthorized Admin Access
ID: 2d949672-7a81-5868-806e-392919238721
STIX ID: report--2d949672-7a81-5868-806e-392919238721
Feed Name: Dark Reading
Threat Score
Ivanti patched a critical authentication-bypass vulnerability (CVE-2024-7593) in Virtual Traffic Manager (vTM) that could allow remote, unauthenticated attackers to reach the admin panel and create administrator accounts; a proof-of-concept exploit is publicly available though Ivanti reports no observed customer exploitation. Patched vTM versions and configuration mitigations (restricting management interface exposure) are provided and recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
