Ivanti warns of critical vTM auth bypass with public exploit

Teilen:

​Today, Ivanti urged customers to patch a critical authentication bypass vulnerability impacting Virtual Traffic Manager (vTM) appliances that can let attackers create rogue administrator accounts.

Ivanti vTM is a software-based application delivery controller (ADC) that provides app-centric traffic management and load balancing for hosting business-critical services.

Tracked as CVE-2024-7593, this auth bypass vulnerability is due to an incorrect implementation of an authentication algorithm that allows remote unauthenticated attackers to bypass authentication on Internet-exposed vTM admin panels.

“Ivanti released updates for Ivanti Virtual Traffic Manager (vTM) which addressed a critical vulnerability. Successful exploitation could lead to authentication bypass and creation of an administrator user,” the company warned on Tuesday.

“We are not aware of any customers being exploited by this vulnerability at the time of disclosure. However, a Proof of Concept is publicly available, and we urge customers to upgrade to the latest patched version. ”

Ivanti advises admins to restrict access to the vTM management interface by binding it to an internal network or private IP address to reduce the attack surface and block potential exploitation attempts.

To limit admin access to the management interface through the private/corporate network, admins have to:

  1. Navigate to System > Security, then click the drop-down for the Management IP Address and Admin Server Port section of the page.
  2. In the ‘bindip’ drop-down, select the Management Interface IP Address or use the setting directly above the “bindip” setting to restrict access to trusted IP addresses, further limiting who can access the interface.

The security flaw has been fixed in Ivanti vTM 22.2R1 and 22.7R2, with patches to be released for the remaining supported versions over the coming weeks.

Ivanti says it has no evidence that the CVE-2024-7593 auth bypass has been exploited in attacks but advised admins to check the Audit Logs Output for new ‘user1’ or ‘user2’ admin users added via the GUI or using the publicly available exploit code.

Today, Ivanti also warned admins to immediately patch an information disclosure vulnerability (CVE-2024-7569) in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier. This vulnerability can let unauthenticated attackers obtain the OIDC client secret via debug information.

The company patched another authentication bypass flaw (CVE-2024-22024) impacting Ivanti Connect Secure, Policy Secure, and ZTA gateways in February when it urged admins to secure vulnerable appliances immediately.

Ivanti VPN appliances have been under attack since December 2023 using exploits chaining the CVE-2023-46805 authentication bypass and the CVE-2024-21887 command injection flaws as zero days.

The company also warned of a third zero-day (a server-side request forgery bug tracked as CVE-2024-21893) under mass exploitation in February, allowing threat actors to bypass authentication on unpatched ICS, IPS, and ZTA gateways.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:25 pm, Jan. 22, 2025
Wetter-Symbol 4°C
L: 4° | H: 5°
haze
Luftfeuchtigkeit: 89 %
Druck: 1003 mb
Wind: 7 mph WNW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 5 km
Sonnenaufgang: 7:52 am
Sonnenuntergang: 4:31 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
4° | 5°°C 0 mm 0% 3 mph 87 % 1003 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 7°°C 1 mm 100% 16 mph 89 % 1005 mb 0 mm/h
Fr. Jan. 24 9:00 pm
Wetter-Symbol
5° | 11°°C 1 mm 100% 24 mph 89 % 1003 mb 0 mm/h
Sa. Jan. 25 9:00 pm
Wetter-Symbol
3° | 6°°C 1 mm 100% 7 mph 88 % 1012 mb 0 mm/h
So. Jan. 26 9:00 pm
Wetter-Symbol
3° | 7°°C 0.2 mm 20% 15 mph 89 % 1011 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
3° | 4°°C 0 mm 0% 3 mph 87 % 1003 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 85 % 1003 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 4 mph 75 % 1003 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 5 mph 83 % 1005 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 7 mph 86 % 1004 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 10 mph 88 % 1003 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
7° | 7°°C 1 mm 100% 15 mph 89 % 999 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
6° | 6°°C 1 mm 100% 16 mph 88 % 998 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,390.05
1.46%
Ethereum(ETH)
€3,154.55
0.17%
XRP(XRP)
€3.05
2.41%
Fesseln(USDT)
€0.96
0.10%
Solana(SOL)
€245.84
7.49%
Dogecoin(DOGE)
€0.347648
-2.81%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000019
-1.27%
Pepe(PEPE)
€0.000015
0.48%
Peanut das Eichhörnchen(PNUT)
€0.345465
-2.46%
Nach oben scrollen