LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-7593: Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 24, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 15, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-7593 to its Known Exploited Vulnerabilities catalog on Sep 24, 2024, with a federal patch deadline of Oct 15, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account.

CVE-2024-7593 is an authentication bypass vulnerability in Ivanti Virtual Traffic Manager. A remote, unauthenticated attacker can create a chosen administrator account on the appliance. Because Virtual Traffic Manager often sits at the edge of networks and controls traffic distribution, a successful bypass can give an attacker full administrative control of a critical infrastructure component. That level of access matters for any organization that relies on the product for load balancing or application delivery.

Public detail is limited to the CWE classifications and the CISA summary; exact affected versions, attack vectors, and patch identifiers must be confirmed against the vendor advisory.

How it works

The vulnerability is classified under CWE-287 (Improper Authentication) and CWE-303 (Incorrect Implementation of Authentication Algorithm). In practice this means the product fails to enforce authentication correctly on a path that allows account creation. An unauthenticated remote attacker can therefore invoke that path and provision a new administrator account of their choosing. Once the account exists, the attacker can log in with full privileges and reconfigure the traffic manager, intercept or redirect traffic, or use the device as a foothold deeper into the environment. No further exploit mechanics are provided in the public record; defenders should treat any unauthenticated administrative action as potentially malicious until proven otherwise.

Am I affected? How to find it in your systems

Ivanti Virtual Traffic Manager is typically deployed as a hardware appliance, virtual appliance, or cloud instance that terminates or load-balances application traffic. Inventory efforts should therefore focus on network edge, DMZ, and data-center load-balancing tiers.

If version information is unavailable or ambiguous, treat the instance as potentially vulnerable until the vendor advisory confirms otherwise.

How to remediate

The primary remediation is to apply the vendor-supplied update that addresses CVE-2024-7593. Follow the installation and reboot guidance in the official Ivanti advisory exactly; do not rely on third-party summaries for version numbers or package names.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls that limit who can reach the vulnerable interface and what can be done once reached.

If your data may have been exposed

Actively exploited authentication-bypass vulnerabilities frequently lead to full system compromise and subsequent data exposure. Although ransomware use of this specific CVE is not documented, any successful creation of an unauthorized administrator account should be treated as a potential breach. Review logs for evidence of account creation and subsequent activity, isolate affected appliances, and follow your incident-response plan. As an additional check, you can run a free exposure scan of your email addresses against known breach data sets to determine whether credentials or personal information associated with your organization have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Virtual Traffic Manager
WeaknessCWE-287
Added to CISA KEVSep 24, 2024
Federal patch deadlineOct 15, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities