ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Critical Flaw in Ivanti Virtual Traffic Manager Could Allow Rogue Admin Access

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38652
+4 in the same advisory: …38653 …37399 …36136 …37373
Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary fi

Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.

NVD description · AI analysis pending
9.1
group max
8%
  • ivanti avalanche
CVE-2024-7569
+1 in the same advisory: …7570
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the

An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.

NVD description · AI analysis pending
9.8
group max
2%
  • ivanti neurons for itsm
CVE-2024-7593
Unauthenticated Admin Account Creation in Ivanti Virtual Traffic Manager

CVE-2024-7593 is an authentication bypass (CWE-287, CWE-303) in Ivanti Virtual Traffic Manager (vTM), Ivanti's enterprise load-balancing and traffic-management product. An unauthenticated remote attacker can send crafted requests to the vulnerable management interface and create an administrator account of their choosing, effectively obtaining full administrative control. With admin access, an attacker can modify load-balancing and traffic-routing configurations and potentially pivot further into the networks the appliance serves. Any organization running an affected Ivanti vTM release is exposed; the affected version ranges are not specified in the available data, so administrators should consult Ivanti's advisory. Exploitation is confirmed in the wild (added to CISA KEV on 2024-09-24), EPSS assigns a 100% probability of exploitation within 30 days (top percentile), CVSS is not yet scored, no public proof-of-concept is known, and ransomware use is unknown.

Do: Upgrade Virtual Traffic Manager to the fixed releases listed in Ivanti's security advisory for CVE-2024-7593; if patching is not immediately possible, follow vendor mitigations or discontinue use, as required under the CISA KEV listing (added 2024-09-24). In the meantime, restrict management-interface access to trusted networks and audit administrator accounts for unexpected or attacker-created admin entries.

9.8100% KEV
  • Ivanti Virtual Traffic Manager
moderateroughly 2,000-3,000 internet-exposed vTM instances (low thousands per public scans); total enterprise installs higher
Full article397 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 14, 2024Vulnerability / Network Security

Ivanti has rolled out security updates for a critical flaw in Virtual Traffic Manager (vTM) that could be exploited to achieve an authentication bypass and create rogue administrative users.

The vulnerability, tracked as CVE-2024-7593, has a CVSS score of 9.8 out of a maximum of 10.0.

"Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel," the company said in an advisory.

It impacts the following versions of vTM -

  • 22.2 (fixed in version 22.2R1)
  • 22.3 (fixed in version 22.3R3, available week of August 19, 2024)
  • 22.3R2 (fixed in version 22.3R3, available week of August 19, 2024)
  • 22.5R1 (fixed in version 22.5R2, available week of August 19, 2024)
  • 22.6R1 (fixed in version 22.6R2, available week of August 19, 2024)
  • 22.7R1 (fixed in version 22.7R2)

As temporary mitigation, Ivanti is recommending customers to limit admin access to the management interface or restrict access to trusted IP addresses.

While there is no evidence that the flaw has been exploited in the wild, it acknowledged the public availability of a proof-of-concept (PoC), making it essential that users apply the latest fixes as soon as possible.

Separately, Ivanti has also addressed two shortcomings in Neurons for ITSM that could result in information disclosure and gain unauthorized access to the devices as any user -

  • CVE-2024-7569 (CVSS score: 9.6) - An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information
  • CVE-2024-7570 (CVSS score: 8.3) - Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user

The issues, which affect versions 2023.4, 2023.3, and 2023.2, have been resolved in versions 2023.4 w/ patch, 2023.3 w/ patch, and 2023.2 w/ patch, respectively.

Also patched by the company are five high-severity flaws (CVE-2024-38652, CVE-2024-38653, CVE-2024-36136, CVE-2024-37399, and CVE-2024-37373) in Ivanti Avalanche that could be exploited to achieve a denial-of-service (DoS) condition or remote code execution. They have been fixed in version 6.4.4.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/08/critical-flaw-in-ivanti-virtual-traffic.html