ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Ivanti vTM auth bypass flaw exploited in attacks, CISA warns (CVE-2024-7593)

criticalVulnerability exploited in the wildimportance 60CVE-2024-7593

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-7593
Unauthenticated Admin Account Creation in Ivanti Virtual Traffic Manager

CVE-2024-7593 is an authentication bypass (CWE-287, CWE-303) in Ivanti Virtual Traffic Manager (vTM), Ivanti's enterprise load-balancing and traffic-management product. An unauthenticated remote attacker can send crafted requests to the vulnerable management interface and create an administrator account of their choosing, effectively obtaining full administrative control. With admin access, an attacker can modify load-balancing and traffic-routing configurations and potentially pivot further into the networks the appliance serves. Any organization running an affected Ivanti vTM release is exposed; the affected version ranges are not specified in the available data, so administrators should consult Ivanti's advisory. Exploitation is confirmed in the wild (added to CISA KEV on 2024-09-24), EPSS assigns a 100% probability of exploitation within 30 days (top percentile), CVSS is not yet scored, no public proof-of-concept is known, and ransomware use is unknown.

Do: Upgrade Virtual Traffic Manager to the fixed releases listed in Ivanti's security advisory for CVE-2024-7593; if patching is not immediately possible, follow vendor mitigations or discontinue use, as required under the CISA KEV listing (added 2024-09-24). In the meantime, restrict management-interface access to trusted networks and audit administrator accounts for unexpected or attacker-created admin entries.

9.8100% KEV
  • Ivanti Virtual Traffic Manager
moderateroughly 2,000-3,000 internet-exposed vTM instances (low thousands per public scans); total enterprise installs higher
Full article331 words · extracted from helpnetsecurity.com · click to collapse

CVE-2024-7593, a critical authentication bypass vulnerability affecting Ivanti Virtual Traffic Manager (vTM) appliances, is actively exploited by attackers.

CVE-2024-7593 exploited

The confirmation comes from the Cybersecurity and Infrastructure Security Agency (CISA), which added the flaw to its Known Exploited Vulnerabilities catalog, thus mandating all US federal civilian executive branch agencies to remediate it by October 15, 2024.

About CVE-2024-7593

Ivanti Virtual Traffic Manager is a software-based application delivery controller and load balancing solution. It includes a web-based administration interface through which traffic across Ivanti Virtual Traffic Manager clusters can be monitored.

CVE-2024-7593 stems from the incorrect implementation of an authentication algorithm in Ivanti vTM versions older than versions 22.2R1, 22.3R3, 22.5R2, 22.6R2 or 22.7R2.

As the company confirmed on August 12, the vulnerability may allow a remote unauthenticated attacker to bypass authentication of the admin panel and to create an admin user.

“This vulnerability is accessible over the management interface. To limit exploitability of this vulnerability, it is industry best practice and advised by Ivanti to limit Admin Access to the Management Interface internal to the network through the private / corporate network,” they added.

At the time, Ivanti confirmed the public availability of proof-of-concept exploit code, but said that they were not aware of customers being targeted via this vulnerability.

What to do?

Ivanti devices – VPN appliances, gateways, and Cloud Services Appliances – have lately been targeted by attackers wielding zero and n-day vulnerabilities, pushing the company to improve security practices and accelerate security initiatives.

After Ivanti’s release of the last patches on August 19, Censys searched for internet-exposed Ivanti vTM devices and found 97 of them.

Admins are urged to upgrade to fixed vTM versions and/or to limit access to the management interface, and to review the “Audit Logs Output” for specific indicators of new admin users having been added via the GUI or by exploit code.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/09/25/cve-2024-7593-exploited/