25 September 2024

High-severity Ivanti VTM auth bypass bug exploited in the wild


High-severity Ivanti VTM auth bypass bug exploited in the wild

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a high-risk Ivanti Virtual Traffic Manager authentication bypass vulnerability it to its Known Exploited Vulnerabilities (KEV) catalog.

Tracked as CVE-2024-7593, the flaw allows a remote attacker to compromise the target system. The issue exists due to incorrect implementation of authentication algorithm. A remote attacker can bypass authentication of the admin panel. Virtual Traffic Manager versions 22.2 - 22.7R1 are said to be impacted.

Earlier this month, CISA flagged another critical Ivanti vulnerability - CVE-2024-8963. The flaw, present in unpatched CSA systems, allows remote, unauthenticated attackers to bypass administrative controls and access restricted functionalities.

Attackers are chaining CVE-2024-8963 with the command injection bug CVE-2024-8190 to gain elevated access. The latter was patched last week. Through the chained exploits, attackers can bypass admin authentication entirely, allowing them to execute arbitrary commands on compromised systems.


Back to the list

Latest Posts

Cyber Security Week in Review: September 27, 2024

Cyber Security Week in Review: September 27, 2024

In brief: The US sanctions Russian crypto exchanges, the Chinese hackers reportedly infiltrate US ISPs, and more.
27 September 2024
New RomCom variant spotted in espionage campaigns

New RomCom variant spotted in espionage campaigns

The most recent variant uses valid code-signing certificates to evade detection.
26 September 2024
China-linked Salt Typhoon hackers reportedly infiltrate US ISPs

China-linked Salt Typhoon hackers reportedly infiltrate US ISPs

The attackers are suspected of targeting core network infrastructure, specifically routers, to gain access to confidential data.
26 September 2024