ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-35138
+2 in the same advisory: …35137 …3391
The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details dur

The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details during the authentication process, as demonstrated by Mobile@Work (aka com.mobileiron). The key is in the com/mobileiron/common/utils/C4928m.java file. NOTE: It has been asserted that there is no causality or connection between credential encryption and the MiTM attack

NVD description · AI analysis pending
9.8
group max
1% PoC ×3
  • mobileiron mobile\@work
CVE-2020-15506
+1 in the same advisory: …15507
An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0

An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to bypass authentication mechanisms via unspecified vectors.

NVD description · AI analysis pending
9.8
group max
3%
  • mobileiron cloud
  • mobileiron core
  • mobileiron enterprise connector
  • +1 more
CVE-2020-15505
Unauthenticated Hessian Java Deserialization RCE in Ivanti MobileIron

CVE-2020-15505 is a critical, unauthenticated remote code execution vulnerability in Ivanti MobileIron's Core and Enterprise Connector, Sentry, and Monitor and Reporting Database (RDB) products, which public proof-of-concept exploits identify as a Hessian-based Java deserialization flaw. An unauthenticated attacker can send crafted requests to an affected MobileIron server over the network, with no privileges or user interaction required, and execute arbitrary code, gaining full control of the MDM server with high impact on confidentiality, integrity, and availability. Any organization running the affected versions of these enterprise mobile device management products is at risk, particularly internet-facing MobileIron Core and Sentry instances. Exploitation is confirmed and widespread: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added November 3, 2021), carries a 99.7% EPSS score, and was named among the top flaws exploited by Chinese state-sponsored hackers, prompting urgent UK NCSC patching alerts. It is also being observed chained with other exploited vulnerabilities (e.g., VPN flaws and Zerologon) as an initial-access vector, so defenders should treat it as actively exploited.

Do: Apply the vendor updates immediately per Ivanti's security advisory for MobileIron Core, Enterprise Connector, Sentry, and RDB (this is CISA's required action for KEV entries). Until patched, reduce internet exposure of MobileIron interfaces and monitor for exploitation; because the flaw was mass-exploited (including by Chinese state-sponsored actors), hunt for signs of compromise such as unexpected processes, persistence mechanisms, or webshells on affected MDM servers.

9.8100% KEV PoC ×2
  • Ivanti (MobileIron) MobileIron Core 10.3.0.3 and earlier; 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3; 10.5.1.0, 10.5.2.0; 10.6.0.0
  • Ivanti (MobileIron) Enterprise Connector 10.3.0.3 and earlier; 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3; 10.5.1.0, 10.5.2.0; 10.6.0.0 (same version set as Core)
  • Ivanti (MobileIron) Sentry 9.7.2 and earlier; 9.8.0
  • +1 more
largeon the order of 10,000+ internet-exposed MobileIron servers, reaching millions of managed endpoints through enterprise MDM deployments (estimate)