Third Ivanti Bug Comes Under Active Exploit, CISA Warns

  /     /     /  
Publicated : 23/11/2024   Category : security


Third Ivanti Bug Comes Under Active Exploit, CISA Warns


Though the critical vulnerability was patched in August, Ivanti is reminding customers to update as soon as possible as attacks from unauthenticated threat actors start circulating.



The Cybersecurity and Infrastructure Security Agency (CISA) has added a third Ivanti vulnerability to the agencys Known Exploited Vulnerabilities (KEV) Catalog in as many weeks.
CVE-2024-7593
 is a virtual traffic manager authentication bypass vulnerability that could be exploited by a remote unauthenticated attacker to bypass the admin panel and create their own admin accounts. The vulnerability stems from incorrect implementation of an authentication algorithm in older versions of Ivanti vTM.
The bug was given a 
high-severity core of 9.8
 and was patched with the release of vTM versions 22.2R1, 22.3R3, 22.5R2, 22.6R2, and 22.7R2 in August. 
At the time, Ivanti noted that a 
proof-of-concept was available
 and that customers should upgrade to the latest patched version of vTM as soon as possible. However, its unclear whether the vulnerability is being exploited in the wild and, if so, who might be behind it.
As noted, this wouldnt be the first Ivanti vulnerability to come under active exploitation in recently; two flaws affecting the vendors Cloud Service Appliance — 
CVE-2024-8963
and
CVE-2024-8190
— have also been exploited by malicious actors.

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Third Ivanti Bug Comes Under Active Exploit, CISA Warns