EXPOSURES › CVE-2024-7593
CVE-2024-7593
HIGH ⌖ ON CISA KEV · EXPLOITEDIvanti Virtual Traffic Manager allows remote attackers to create admin accounts via an authentication bypass.
This vulnerability enables remote, unauthenticated attackers to bypass authentication and create administrator accounts, granting full administrative control. DIB organizations must patch immediately to prevent unauthorized admin creation and potential lateral movement, as this bypasses core security controls required by NIST 800-171.
Shame score — The vulnerability allows complete bypass of authentication controls to create admin accounts, representing a critical failure in identity management and access control.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account.
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |