Target Industry

Indiscriminate, opportunistic targeting.

Overview

The US Cybersecurity and Infrastructure Security Agency (CISA) has recently added a significant Ivanti vulnerability, CVE-2024-7593, to its Known Exploited Vulnerabilities (KEV) Catalogue. CVE-2024-7593 has been assigned a CVSS score of 9.8, categorising it as a high-severity vulnerability. This vulnerability in Ivanti’s Virtual Traffic Manager (vTM) allows a remote, unauthenticated attacker to bypass the admin panel’s authentication and potentially create their own admin accounts. The issue, stemming from an incorrect implementation of an authentication algorithm, affects older versions of Ivanti vTM.

Impact

This flaw allows attackers to gain unauthorised access to the admin panel, potentially leading to a complete system compromise. With a CVSS v3.1 base score of 9.8, this vulnerability is classified as critically severe. It does not require any user interaction, can be exploited remotely over the network, and does not necessitate any special privileges, making it relatively straightforward for attackers to leverage. Attackers could view sensitive information, alter system configurations, and disrupt normal operations of the Ivanti vTM.

Vulnerability Detection

Ivanti has released a security update addressing the security flaw in the respective product versions. As such, previous versions are vulnerable to potential exploits.

Exploitation

The vulnerability is actively being exploited in the wild and was added to the CISA Known Exploited Vulnerability list.

Containment, Mitigations & Remediations

The vulnerability is not present in Ivanti vTM versions 22.2R1 and 22.7R2, indicating that these versions have been patched to address the issue. We strongly recommend that users of affected Ivanti systems apply the update as soon as possible.

Threat Landscape

Ivanti occupies a significant portion of the mobile-device-management market share. Given that threat actors generally use a combination of probability and asset value to determine which attack surfaces to focus on, related products will likely emerge as a prime target. Since Ivanti products have become an integral aspect of business operations, threat actors will continue to exploit the associated vulnerabilities in an attempt to exfiltrate sensitive data contained therein.

Threat Group

No attribution to specific threat actors or groups has been identified at the time of writing.

Further Information

https://www.cisa.gov/news-events/alerts/2024/09/24/cisa-adds-one-known-exploited-vulnerability-catalog https://nvd.nist.gov/vuln/detail/CVE-2024-7593 https://www.securityweek.com/third-recent-ivanti-product-vulnerability-exploited-in-the-wild/ https://thehackernews.com/2024/08/critical-flaw-in-ivanti-virtual-traffic.html https://www.infosecurity-magazine.com/news/critical-ivanti-auth-bypass-bug/

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content