CVE-2024-7593

critical KEV
Published 2024-08-13 · Modified 2024-09-24
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
10.0

Description

Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account.

CISA KEV

Vendor
Ivanti
Product
Virtual Traffic Manager
Due date
2024-10-15

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593 ; https://nvd.nist.gov/vuln/detail/CVE-2024-7593

vendor Authored 2026-05-27

Vendor advisory: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75 — https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593

Exploits

Application impact

VendorProductVersionsFixed
ivantivirtual_traffic_manager22.2
ivantivirtual_traffic_manager22.3
ivantivirtual_traffic_manager22.5
ivantivirtual_traffic_manager22.6
ivantivirtual_traffic_manager22.7

References

CWEs

CWE-287 CWE-303

Verify integrity in audit chain (admin only). AS-IS.