CVE-2020-15505
KEV PoC ×2largeUnauthenticated Hessian Java Deserialization RCE in Ivanti MobileIron
CISA: Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability
CVE-2020-15505 is a critical, unauthenticated remote code execution vulnerability in Ivanti MobileIron's Core and Enterprise Connector, Sentry, and Monitor and Reporting Database (RDB) products, which public proof-of-concept exploits identify as a Hessian-based Java deserialization flaw. An unauthenticated attacker can send crafted requests to an affected MobileIron server over the network, with no privileges or user interaction required, and execute arbitrary code, gaining full control of the MDM server with high impact on confidentiality, integrity, and availability. Any organization running the affected versions of these enterprise mobile device management products is at risk, particularly internet-facing MobileIron Core and Sentry instances. Exploitation is confirmed and widespread: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added November 3, 2021), carries a 99.7% EPSS score, and was named among the top flaws exploited by Chinese state-sponsored hackers, prompting urgent UK NCSC patching alerts. It is also being observed chained with other exploited vulnerabilities (e.g., VPN flaws and Zerologon) as an initial-access vector, so defenders should treat it as actively exploited.
What to do: Apply the vendor updates immediately per Ivanti's security advisory for MobileIron Core, Enterprise Connector, Sentry, and RDB (this is CISA's required action for KEV entries). Until patched, reduce internet exposure of MobileIron interfaces and monitor for exploitation; because the flaw was mass-exploited (including by Chinese state-sponsored actors), hunt for signs of compromise such as unexpected processes, persistence mechanisms, or webshells on affected MDM servers.
| Ivanti (MobileIron) MobileIron Core | 10.3.0.3 and earlier; 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3; 10.5.1.0, 10.5.2.0; 10.6.0.0 |
| Ivanti (MobileIron) Enterprise Connector | 10.3.0.3 and earlier; 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3; 10.5.1.0, 10.5.2.0; 10.6.0.0 (same version set as Core) |
| Ivanti (MobileIron) Sentry | 9.7.2 and earlier; 9.8.0 |
| Ivanti (MobileIron) Monitor and Reporting Database (RDB) | 2.0.0.1 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier that allows remote attackers to execute arbitrary code via unspecified vectors.
- Affected
- Ivanti MobileIron Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- mobileiron
- Products
- core, enterprise connector, monitor and reporting database, sentry
- Weakness
- CWE-706
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H