Hackers exploited Ivanti zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-35078 | Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) Exposes PII Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass (CWE-287) that allows a remote, unauthenticated attacker to access specific API paths on a vulnerable server. Because these endpoints require no credentials, any attacker who can reach the server can invoke them directly. Through these paths an attacker can read PII such as user names, phone numbers, and mobile device details, and can also make configuration changes, including installing software and modifying security profiles on enrolled devices, giving attackers a lever into the managed mobile fleet. Organizations running EPMM, typically enterprises and government agencies using it for mobile device management, are affected; exact affected version ranges should be taken from Ivanti's advisory. The flaw is actively exploited: it was added to CISA's KEV on 2023-07-25 with known ransomware use, EPSS is ~100%, while no public PoC or CVSS score is yet available. Do: Apply Ivanti's patched EPMM releases per the vendor's instructions immediately, as patching or discontinuing use is the CISA KEV required action. Hunt for unauthenticated requests to the affected API paths, and review enrolled devices for unexpected software installs or modified security profiles, since ransomware operators are known to have used this flaw. Verify internet-exposed EPMM servers are prioritized for remediation and that managed-device configurations have not been tampered with. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of deployed EPMM instances (enterprise/government MDM), with several thousand internet-exposed |
Full article407 words · extracted from therecord.media · click to collapse
Hackers exploited a zero-day vulnerability in tech giant Ivanti’s software to compromise a dozen Norwegian government agencies. Norwegian security officials said on Monday that the flaw was found in Ivanti’s mobile endpoint management software used by the impacted ministries. “This vulnerability was unique, and was discovered for the very first time here in Norway,” said Sofie Nystrøm, director of Norway’s National Security Agency. “If we had released the information about the vulnerability too early, it could have contributed to it being misused elsewhere in Norway and in the rest of the world.” The attack has caused some disruptions at the impacted ministries, but did not widely affect government operations. The government has alerted the Norwegian data protection agency about the incident, raising concerns that the hackers could have potentially accessed or extracted sensitive data from the compromised systems. The government has also warned other Norwegian businesses using the same software about the zero-day. Ivanti’s software is used by dozens of governments around the world. The company recently patched the vulnerability — tracked as CVE-2023-35078 — and is “actively engaging with customers to help them apply the fix,” an Ivanti spokesperson told Recorded Future News. On Monday, the company issued an advisory stating that it’s currently aware of a "very limited number of customers" who have been impacted by the hack. The vulnerability received the highest CVSS score — a 10 out of 10 — signifying that it is a critical bug that should be given immediate attention. According to the U.S. Cybersecurity and Infrastructure Security Agency, the vulnerability could allow hackers to remotely access victims’ personally identifiable information, such as names, phone numbers, and other mobile device details. An attacker can also make other configuration changes, including creating an administrative account that can make further changes to a vulnerable system, CISA said Monday in a security alert. Ivanti faced criticism for its handling of the bug disclosure as it initially restricted access to the flaw's details behind a paywall. The company reportedly asked potentially affected customers to sign a non-disclosure agreement before disclosing the information.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/hackers-use-ivanti-zero-day-to-attack-norway-ministries