Third Ivanti Bug Comes Under Active Exploit, CISA Warns
ID: 9007be36-28aa-5dc3-abdb-92449db7da52
STIX ID: report--9007be36-28aa-5dc3-abdb-92449db7da52
Feed Name: Dark Reading
CISA added Ivanti vTM CVE-2024-7593 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog; the flaw is an authentication-bypass in older vTM versions that could allow a remote unauthenticated attacker to bypass the admin panel and create admin accounts. Ivanti released patches across multiple vTM versions in August and noted a proof-of-concept exists; the report states it is unclear whether the vulnerability is currently being exploited in the wild but highlights that other recent Ivanti vulnerabilities have been exploited.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
