Ivanti warns of critical vTM auth bypass with public exploit
ID: 0fe60332-9788-5aff-8050-54c6738f9a03
STIX ID: report--0fe60332-9788-5aff-8050-54c6738f9a03
Feed Name: Bleeping Computer
Threat Score
Ivanti disclosed a critical authentication bypass vulnerability (CVE-2024-7593) in Virtual Traffic Manager (vTM) that can let remote unauthenticated attackers bypass admin authentication and create rogue administrator accounts; Ivanti released patches for some versions, plans additional fixes, and warns administrators to restrict management interface access and check audit logs, while noting a public proof-of-concept exists and referencing prior exploited Ivanti vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
