ZeroHour

CVE-2020-15505

KEV PoC ×2large

Unauthenticated Hessian Java Deserialization RCE in Ivanti MobileIron

CISA: Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2020-15505 is a critical, unauthenticated remote code execution vulnerability in Ivanti MobileIron's Core and Enterprise Connector, Sentry, and Monitor and Reporting Database (RDB) products, which public proof-of-concept exploits identify as a Hessian-based Java deserialization flaw. An unauthenticated attacker can send crafted requests to an affected MobileIron server over the network, with no privileges or user interaction required, and execute arbitrary code, gaining full control of the MDM server with high impact on confidentiality, integrity, and availability. Any organization running the affected versions of these enterprise mobile device management products is at risk, particularly internet-facing MobileIron Core and Sentry instances. Exploitation is confirmed and widespread: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added November 3, 2021), carries a 99.7% EPSS score, and was named among the top flaws exploited by Chinese state-sponsored hackers, prompting urgent UK NCSC patching alerts. It is also being observed chained with other exploited vulnerabilities (e.g., VPN flaws and Zerologon) as an initial-access vector, so defenders should treat it as actively exploited.

What to do: Apply the vendor updates immediately per Ivanti's security advisory for MobileIron Core, Enterprise Connector, Sentry, and RDB (this is CISA's required action for KEV entries). Until patched, reduce internet exposure of MobileIron interfaces and monitor for exploitation; because the flaw was mass-exploited (including by Chinese state-sponsored actors), hunt for signs of compromise such as unexpected processes, persistence mechanisms, or webshells on affected MDM servers.

Affected
Ivanti (MobileIron) MobileIron Core10.3.0.3 and earlier; 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3; 10.5.1.0, 10.5.2.0; 10.6.0.0
Ivanti (MobileIron) Enterprise Connector10.3.0.3 and earlier; 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3; 10.5.1.0, 10.5.2.0; 10.6.0.0 (same version set as Core)
Ivanti (MobileIron) Sentry9.7.2 and earlier; 9.8.0
Ivanti (MobileIron) Monitor and Reporting Database (RDB)2.0.0.1 and earlier
Estimated exposure
largeon the order of 10,000+ internet-exposed MobileIron servers, reaching millions of managed endpoints through enterprise MDM deployments (estimate) — Estimated from MobileIron's position as a widely deployed enterprise MDM platform and public internet scans reporting tens of thousands of exposed MobileIron instances when the flaw was disclosed, with each MDM server typically managing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier that allows remote attackers to execute arbitrary code via unspecified vectors.

CISA Known Exploited Vulnerability
Affected
Ivanti MobileIron Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
mobileiron
Products
core, enterprise connector, monitor and reporting database, sentry
Weakness
CWE-706
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news