SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP Ivanti Virtual Traffic Manager authentication bypass attempt
This rule looks for the `error` HTTP parameter set to a non-zero value in a request to the `/apps/zxtm/wizard.fcgi` endpoint.
This rule alerts on an authentication bypass attempt in Ivanti vADC.
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
No rule groups
Authentication Bypass
An Authentication Bypass occurs when there is a way to avoid providing user credentials to a system before performing restricted operations on said system.
CVE-2024-7593 |
Loading description
|