Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Third Recent Ivanti Vulnerability Exploited in the Wild

CVE-2024-7593 is the third Ivanti product vulnerability patched in recent months that has been exploited in the wild.

Ivanti vulnerability

A vulnerability affecting Ivanti’s Virtual Traffic Manager application delivery controller is being exploited in the wild. This is the third flaw for which Ivanti customers have received such a warning within the past two weeks. 

The latest is CVE-2024-7593, a critical Virtual Traffic Manager (vTM) authentication bypass vulnerability that allows a remote, unauthenticated attacker to create an administrator account. 

Ivanti announced patches for CVE-2024-7593 on August 12 and later the company updated its advisory to inform customers that while it had not been aware of in-the-wild exploitation a proof-of-concept (PoC) exploit had been made available.

At the time of writing, SecurityWeek has not seen any public reports describing attacks involving CVE-2024-7593, but CISA on Tuesday added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog. 

Ivanti has made available not only fixes, but also recommendations for limiting exploitability, as well as indicators of compromise (IoCs). However, it has yet to update the advisory to mention malicious exploitation. 

Censys has reported seeing 97 internet-exposed Ivanti vTM instances and ZoomEye has seen 164 this year, a majority in the United States and Japan. 

Advertisement. Scroll to continue reading.

CVE-2024-7593 was added to CISA’s KEV list shortly after CVE-2024-8963 and CVE-2024-8190, which impact Ivanti’s Cloud Services Appliance (CSA) and which have been chained for unauthenticated remote code execution. 

It’s not uncommon for threat actors to exploit Ivanti product vulnerabilities. CISA currently has 20 entries in its KEV list for Ivanti vulnerabilities, some of which have been exploited to deliver backdoors and others to hack high-profile organizations such as MITRE and CISA.

Related: MITRE Hack: China-Linked Group Breached Systems in December 2023

Related: Chinese Cyberspies Use New Malware in Ivanti VPN Attacks

Related: Governments Urge Organizations to Hunt for Ivanti VPN Attacks

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.