Hackers Exploit Ivanti vTM Flaw to Create Rogue Admin Accounts

Red | Vulnerability Report
Download PDF

Ivanti has identified a critical authentication bypass vulnerability, designated as CVE-2024-7593, affecting their Virtual Traffic Manager (vTM) appliances. This flaw enables attackers to potentially create unauthorized administrator accounts, significantly increasing the risk of unauthorized access and control over affected systems. With a proof of concept now publicly available, it is imperative that customers upgrade to the latest patched version to mitigate this risk.