Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
# CVE-2024-7593 Detection
## How does this detection method work?
This template matches on the following versions, if there is a match then the host is considered vulnerable:
```
- "22.2"
- "22.3"
- "22.3R2"
- "22.5R1"
- "22.6R1"
- "22.7R1"
```
To prevent producing any FPs it also matches on the below:
```
- type: word
part: body
words:
- "Login (Virtual Traffic Manager"
```
## How do I run this script?
1. Download Nuclei from [here](https://github.com/projectdiscovery/nuclei)
2. Copy the template to your local system
3. Run the following command: `nuclei -u https://yourHost.com -t template.yaml`
## References
- https://arcticwolf.com/resources/blog/cve-2024-7593-cve-2024-7569/
- https://nvd.nist.gov/vuln/detail/CVE-2024-7593
- https://www.tenable.com/blog/cve-2024-7593-ivanti-virtual-traffic-manager-authentication-bypass-vulnerability
## Disclaimer
Use at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view