Security News > 2024 > September > CISA Flags Critical Ivanti vTM Vulnerability Amid Active Exploitation Concerns
2024-09-25 06:01
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw impacting Ivanti Virtual Traffic Manager (vTM) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability in question is CVE-2024-7593 (CVSS score: 9.8), which could be exploited by a remote unauthenticated attacker to bypass the
News URL
https://thehackernews.com/2024/09/cisa-flags-critical-ivanti-vtm.html
Related news
- CISA Warns of Critical Jenkins Vulnerability Exploited in Ransomware Attacks (source)
- CISA Flags Critical Apache OFBiz Flaw Amid Active Exploitation Reports (source)
- Ivanti Warns of Active Exploitation of Newly Patched Cloud Appliance Vulnerability (source)
- Critical Ivanti Cloud Appliance Vulnerability Exploited in Active Cyberattacks (source)
- Critical Progress WhatsUp RCE flaw now under active exploitation (source)
- Ivanti warns of critical vTM auth bypass with public exploit (source)
- Critical Flaw in Ivanti Virtual Traffic Manager Could Allow Rogue Admin Access (source)
- CISA warns critical SolarWinds RCE bug is exploited in attacks (source)
- Microsoft Patches Critical Copilot Studio Vulnerability Exposing Sensitive Data (source)
- CISA Urges Federal Agencies to Patch Versa Director Vulnerability by September (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-08-13 | CVE-2024-7593 | Improper Authentication vulnerability in Ivanti Virtual Traffic Management Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel. | 9.8 |