ZeroHour
Infosecurity Magazinepublished ()ingested Dan Raywood

Ivanti Adds VPN and MDM Technolgies in Double Acquisition

criticalVulnerabilityimportance 60CVE-2019-11510

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-11510
Unauthenticated Arbitrary File Read in Ivanti Pulse Connect Secure VPN

Ivanti Pulse Connect Secure, an enterprise SSL VPN appliance, contains an arbitrary file read vulnerability (CWE-22, path traversal) that requires no authentication. An unauthenticated remote attacker with network access to the appliance over HTTPS can send a specially crafted URI containing traversal sequences to read arbitrary files from the device. The attacker gains access to sensitive appliance files, potentially including configuration or credential material useful for further compromise, and CISA records known ransomware use of this flaw. Any organization running Pulse Connect Secure, especially gateways exposed to the internet for remote access, is affected. Exploitation is established: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a 100% probability of exploitation in the next 30 days, and no public PoC is known.

Do: Apply updates per Ivanti's instructions, the required action in the CISA KEV entry, prioritizing internet-facing Pulse Connect Secure gateways, and consult the vendor advisory for the applicable fixed release since no version range is provided here. Where patching is not immediate, restrict HTTPS access to the appliance and hunt for signs of exploitation (unexpected file reads, anomalous VPN logins or sessions, and follow-on ransomware activity), as CISA reports known ransomware use.

10.0100% KEV ransomware PoC ×2
  • Ivanti Pulse Connect Secure
largeTens of thousands of internet-exposed gateways (order of 10,000-100,000 systems; each typically serves hundreds of VPN users, so potentially millions of users)
Full article317 words · extracted from infosecurity-magazine.com · click to collapse

Ivanti has announced the acquisitions of mobile device management vendor MobileIron and secure access and VPN provider Pulse Secure.

Under the terms of the agreement, Ivanti will acquire all outstanding shares of MobileIron for a total value of approximately $872m. Financial details for the Pulse Secure acquisition have not been disclosed. Ivanti said, by bringing MobileIron and Pulse Secure into its portfolio, organizations will be able to manage and secure users, devices, data and access to ensure that every device in an organization is covered.

Upon completion of the transaction, the combined company will be led by Ivanti chairman and CEO Jim Schaper. “By combining MobileIron and Pulse Secure with Ivanti, we are creating a leader in the large and growing unified endpoint management, security and enterprise service management markets,” he said.

“We now have the most comprehensive set of software solutions that addresses the growing market demand for the future of work,” Schaper added. “With the integration of our industry knowledge and complementary product offerings, Ivanti will be well positioned to provide our expansive customer base with the critical tools needed to tackle IT challenges in the new normal.”

Simon Biddiscombe, CEO of MobileIron, said he was “thrilled to join forces with Ivanti and Pulse Secure” as the a combination will “accelerate MobileIron’s ability to help organizations quickly and securely embrace the future of work, in which employees, IT infrastructures and customers are everywhere – and mobile devices provide access to everything.”

Sudhakar Ramakrishna, CEO of Pulse Secure, said: “We believe that organizations looking for unified endpoint management and secure access solutions will see the combined platform as a new, highly focused partnership with the capabilities to deliver a complete, best-in-class, global solution.”

The announcement follows reports of extensive attacks on Pulse Secure’s VPN solutions. with the US Cybersecurity and Infrastructure Agency issuing an alert advising users to apply a patch for exploit CVE-2019-11510.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ivanti-vpn-mdm-acquisition/