Ivanti Virtual Traffic Manager是美国Ivanti公司的一款基于软件的应用程序交付控制器。 Ivanti vTM 22.2R1版本、22.7R2版本存在安全漏洞,该漏洞源于身份验证算法存在错误。攻击者利用该漏洞可以绕过管理面板的身份验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel. | https://github.com/rxerium/CVE-2024-7593 | POC Details |
| 2 | CVE-2024-7593 Ivanti Virtual Traffic Manager 22.2R1 / 22.7R2 Admin Panel Authentication Bypass PoC [EXPLOIT] | https://github.com/D3N14LD15K/CVE-2024-7593_PoC_Exploit | POC Details |
| 3 | None | https://github.com/skyrowalker/CVE-2024-7593 | POC Details |
| 4 | None | https://github.com/0xlf/CVE-2024-7593 | POC Details |
| 5 | Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-7593.yaml | POC Details |
| 6 | None | https://github.com/zxcod3/CVE-2024-7593 | POC Details |
| 7 | None | https://github.com/0zerobyte/CVE-2024-7593 | POC Details |
| 8 | None | https://github.com/voidbroker/CVE-2024-7593 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-7569 | 9.6 CRITICAL | Ivanti ITSM 安全漏洞 |
| CVE-2024-7570 | 8.3 HIGH | Ivanti ITSM 安全漏洞 |
No comments yet