ZeroHour

CVE-2024-7593

KEVmoderate

Unauthenticated Admin Account Creation in Ivanti Virtual Traffic Manager

CISA: Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2024-7593 is an authentication bypass (CWE-287, CWE-303) in Ivanti Virtual Traffic Manager (vTM), Ivanti's enterprise load-balancing and traffic-management product. An unauthenticated remote attacker can send crafted requests to the vulnerable management interface and create an administrator account of their choosing, effectively obtaining full administrative control. With admin access, an attacker can modify load-balancing and traffic-routing configurations and potentially pivot further into the networks the appliance serves. Any organization running an affected Ivanti vTM release is exposed; the affected version ranges are not specified in the available data, so administrators should consult Ivanti's advisory. Exploitation is confirmed in the wild (added to CISA KEV on 2024-09-24), EPSS assigns a 100% probability of exploitation within 30 days (top percentile), CVSS is not yet scored, no public proof-of-concept is known, and ransomware use is unknown.

What to do: Upgrade Virtual Traffic Manager to the fixed releases listed in Ivanti's security advisory for CVE-2024-7593; if patching is not immediately possible, follow vendor mitigations or discontinue use, as required under the CISA KEV listing (added 2024-09-24). In the meantime, restrict management-interface access to trusted networks and audit administrator accounts for unexpected or attacker-created admin entries.

Affected
Ivanti Virtual Traffic Manager
Estimated exposure
moderateroughly 2,000-3,000 internet-exposed vTM instances (low thousands per public scans); total enterprise installs higher — vTM is a niche enterprise load balancer rather than a mass-market product, and public internet scans (e.g., Shodan/Censys) have historically shown only a few thousand exposed vTM admin interfaces, so the plausible exposure is on the order…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

CISA Known Exploited Vulnerability
Affected
Ivanti Virtual Traffic Manager
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
ivanti
Products
virtual traffic manager
Weakness
CWE-287, CWE-303
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news