Ivanti Patches Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-35078 | Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) Exposes PII Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass (CWE-287) that allows a remote, unauthenticated attacker to access specific API paths on a vulnerable server. Because these endpoints require no credentials, any attacker who can reach the server can invoke them directly. Through these paths an attacker can read PII such as user names, phone numbers, and mobile device details, and can also make configuration changes, including installing software and modifying security profiles on enrolled devices, giving attackers a lever into the managed mobile fleet. Organizations running EPMM, typically enterprises and government agencies using it for mobile device management, are affected; exact affected version ranges should be taken from Ivanti's advisory. The flaw is actively exploited: it was added to CISA's KEV on 2023-07-25 with known ransomware use, EPSS is ~100%, while no public PoC or CVSS score is yet available. Do: Apply Ivanti's patched EPMM releases per the vendor's instructions immediately, as patching or discontinuing use is the CISA KEV required action. Hunt for unauthenticated requests to the affected API paths, and review enrolled devices for unexpected software installs or modified security profiles, since ransomware operators are known to have used this flaw. Verify internet-exposed EPMM servers are prioritized for remediation and that managed-device configurations have not been tampered with. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of deployed EPMM instances (enterprise/government MDM), with several thousand internet-exposed |
Full article347 words · extracted from infosecurity-magazine.com · click to collapse
A major security breach at the Norwegian government announced yesterday has been traced back to a zero-day vulnerability in an Ivanti security product, for which a patch is now available.
Norway’s National Cyber Security Center (NCSC) revealed the news late yesterday local time.
“NCSC wishes to notify of an actively exploited zero-day vulnerability, CVE-2023-35078, in the product Ivanti Endpoint Manager (EPMM), formerly known as MobileIron Core. The vulnerability affects a number of versions of the software,” it said in a statement.
“NCSC has notified all known system owners in Norway who have MobileIron Core available on the internet about the available security update. NCSC recommends that the security updates be installed immediately.”
Read more on zero-day threats: Barracuda Zero-Day Exploited by Chinese Actor
Ivanti released an advisory about authentication bypass vulnerability CVE-2023-35078 on Monday, claiming it impacts all supported versions of the EPMM product.
“If exploited, this vulnerability enables an unauthorized, remote (internet-facing) actor to potentially access users’ personally identifiable information and make limited changes to the server,” the vendor said.
“We have received information from a credible source indicating exploitation has occurred. We continue to work with our customers and partners to investigate this situation. We are only aware of a very limited number of customers that have been impacted. We are actively working with our customers and partners to investigate this situation.”
Given its severity, the CVSS 10.0-rated zero-day bug should be a priority to patch for any affected customer.
Although the details are still unclear, unnamed attackers exploited the zero-day flaw to compromise 12 government ministries in the Scandinavian country. Norway’s National Security Authority (NSM) said that at the time of the press conference announcing the breach it was decided not to reveal the source of the vulnerability.
“If we had released the information about the vulnerability too early, it could have contributed to it being misused elsewhere in Norway and in the rest of the world,” argued NSM director, Sofie Nystrøm.
“The update is now generally available and it is prudent to announce what kind of vulnerability it is.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ivanti-patches-zeroday-bug-norway/