RULE(RULE ID:338405)

Rule General Information
Release Date: 2024-09-10
Rule Name: Ivanti-Virtual-Traffic-Manager Authentication Bypass Vulnerability (CVE-2024-7593)
Severity:
CVE ID:
Rule Protection Details
Description: Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
Impact: An unauthorized remote attacker can bypass authentication and gain access to the application with specially crafted requests.
Affected OS: Windows, Linux, Others
Reference: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593
Solutions
Refer to the announcement or patch by the vendor: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593