Third Ivanti Bug Comes Under Active Exploit, CISA Warns

  /     /     /  
Publicated : 23/11/2024   Category : security


Third Ivanti Bug Comes Under Active Exploit, CISA Warns


Though the critical vulnerability was patched in August, Ivanti is reminding customers to update as soon as possible as attacks from unauthenticated threat actors start circulating.



The Cybersecurity and Infrastructure Security Agency (CISA) has added a third Ivanti vulnerability to the agencys Known Exploited Vulnerabilities (KEV) Catalog in as many weeks.
CVE-2024-7593
 is a virtual traffic manager authentication bypass vulnerability that could be exploited by a remote unauthenticated attacker to bypass the admin panel and create their own admin accounts. The vulnerability stems from incorrect implementation of an authentication algorithm in older versions of Ivanti vTM.
The bug was given a 
high-severity core of 9.8
 and was patched with the release of vTM versions 22.2R1, 22.3R3, 22.5R2, 22.6R2, and 22.7R2 in August. 
At the time, Ivanti noted that a 
proof-of-concept was available
 and that customers should upgrade to the latest patched version of vTM as soon as possible. However, its unclear whether the vulnerability is being exploited in the wild and, if so, who might be behind it.
As noted, this wouldnt be the first Ivanti vulnerability to come under active exploitation in recently; two flaws affecting the vendors Cloud Service Appliance — 
CVE-2024-8963
and
CVE-2024-8190
— have also been exploited by malicious actors.

Last News

▸ Travel agency fined £150,000 for breaking Data Protection Act. ◂
Discovered: 23/12/2024
Category: security

▸ 7 arrested, 3 more charged in StubHub cyber fraud ring. ◂
Discovered: 23/12/2024
Category: security

▸ Nigerian scammers now turning into mediocre malware pushers. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Third Ivanti Bug Comes Under Active Exploit, CISA Warns