CISA has added another Ivanti vulnerability to the Catalog of Exploitable Vulnerabilities (KEV) , which could allow attackers to create fake admin accounts on vulnerable devices with Virtual Traffic Manager (vTM).

The vulnerability is tracked as CVE-2024-7593 and is actively being exploited in attacks. It is an bypass authentication, caused by a misapplication of an authentication algorithm. It allows remote, unauthorized attackers to bypass control in vTM admin panels exposed to the Internet and infiltrate for further compromise.
See also: Ivanti warns of new CSA vulnerability
Ivanti vTM is a software-based application delivery controller (ADC) that provides load balancing and traffic management for hosting business- services.
“Successful exploitation could lead to authentication bypass and creation of an administrator user,” Ivanti said when it patched the vulnerability.
A PoC exploit had already been circulating online since August 13, when the company's patch was released . Ivanti recommends applying the updates immediately and suggests checking Audit Logs Outputfor possible new admin users "user1" or "user2" that have been added.
See also: PoC exploit for critical vulnerability in Ivanti Endpoint Manager
The company also advised administrators to restrict access to the Ivanti vTM management interface, keeping it to an internal network or private IP address.
CISA added the Ivanti vTM vulnerability to the KEV list and ordered federal agencies to secure vulnerable devices on their networks by October 15.
CISA's KEV list primarily alerts federal agencies about security vulnerabilities that need to be patched, but private organizations must also update their systems.

CISA: KEV Directory
CISA's KEV list is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.
Overall, CISA helps a lot in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, state governments, and local authorities, to improve the security of digital systems.
See also: Ivanti: CSA vulnerability used in attacks
It provides information and tools to help organizations protect their networks from cyberattacks and respond to any attacks that may occur. It also informs the public about any vulnerabilities in widely used systems and applications.
Overall, CISA's role is vital to protecting the digital infrastructure of the US and other regions.
Source: www.bleepingcomputer.com
