VDB

CVE-2024-7593

CVE-2024-7593 PUBLISHED KEV CVSS 9.800000190734863 CRITICAL

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

EPSS 94.44% · 100.0th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
94.44%
100.0th percentile

Affected Products

VendorProductVersions
ivantivirtual_traffic_management22.2, 22.7, 22.6
ivantivirtual_traffic_manager22.6r1, 22.5r1, 22.2
IvantivTM*, 22.2R1, 22.2R1

Timeline

  • Jan 20, 1970 VulnCheck XDB Entry
  • Jan 21, 1970 VulnCheck XDB Entry
  • Aug 6, 2024 VulnCheck KEV Exploitation
  • Aug 13, 2024 CVE Published
  • Aug 14, 2024 EPSS Score
  • Aug 27, 2024 PoC Published
  • Sep 3, 2024 PoC Published
  • Sep 4, 2024 EPSS Score
  • Sep 6, 2024 VulnCheck KEV Exploitation
  • Sep 7, 2024 EPSS Score
  • Sep 14, 2024 VulnCheck KEV Exploitation
  • Sep 16, 2024 VulnCheck KEV Exploitation
Open in Interactive Console →
$ Console Community · 100/wk Open console ›