September 24, 2024 · Applied Cybernetics Group
CVE-2024-7593 — Ivanti Virtual Traffic Manager
Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability
- Added to KEV
2024-09-24- Federal due date
2024-10-15- Vendor
- Ivanti
- Product
- Virtual Traffic Manager
- EPSS
- 100.0th percentile (score 0.944, as of
2026-06-08) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2024-7593
CISA short description
Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
NVD description
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.