CISA Known Exploited Vulnerability

CVE-2024-7593

Ivanti · Virtual Traffic Manager

Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

Date added
BOD 22-01 due date
CWE CWE-287, CWE-303
Ransomware Unknown

CISA description

Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.