ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Ivanti Urges Customers to Patch 13 Critical Vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-35078
Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) Exposes PII

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass (CWE-287) that allows a remote, unauthenticated attacker to access specific API paths on a vulnerable server. Because these endpoints require no credentials, any attacker who can reach the server can invoke them directly. Through these paths an attacker can read PII such as user names, phone numbers, and mobile device details, and can also make configuration changes, including installing software and modifying security profiles on enrolled devices, giving attackers a lever into the managed mobile fleet. Organizations running EPMM, typically enterprises and government agencies using it for mobile device management, are affected; exact affected version ranges should be taken from Ivanti's advisory. The flaw is actively exploited: it was added to CISA's KEV on 2023-07-25 with known ransomware use, EPSS is ~100%, while no public PoC or CVSS score is yet available.

Do: Apply Ivanti's patched EPMM releases per the vendor's instructions immediately, as patching or discontinuing use is the CISA KEV required action. Hunt for unauthenticated requests to the affected API paths, and review enrolled devices for unexpected software installs or modified security profiles, since ransomware operators are known to have used this flaw. Verify internet-exposed EPMM servers are prioritized for remediation and that managed-device configurations have not been tampered with.

9.8100% KEV ransomware PoC
  • Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core)
largetens of thousands of deployed EPMM instances (enterprise/government MDM), with several thousand internet-exposed
CVE-2023-35081
Authenticated Path Traversal in Ivanti Endpoint Manager Mobile (EPMM)

CVE-2023-35081 is a path traversal (CWE-22) vulnerability in Ivanti Endpoint Manager Mobile (EPMM), the on-premises mobile device management appliance formerly known as MobileIron Core. It is triggered when an authenticated administrator submits crafted path input, allowing the attacker to write arbitrary files onto the appliance outside intended directories. Because arbitrary files can be written to the appliance, the flaw can be leveraged to further compromise the device, and public reporting indicates it was used in real-world attacks alongside a previously disclosed EPMM authentication bypass. Organizations running EPMM 11.8.x, 11.9.x, or 11.10.x prior to the fixed builds are affected. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-31, attacks on Norwegian government entities have been reported, and no public PoC is known.

Do: Upgrade EPMM to 11.10.0.3, 11.9.1.2, or 11.8.1.2 for the 11.10.x, 11.9.x, and 11.8.x branches respectively, and treat this as urgent given the CISA KEV listing. Until patched, restrict internet-facing access to the EPMM appliance and review the device for unexpected or newly written files and other signs of compromise. Administrators should also confirm they are not exposed via chaining with the previously disclosed EPMM authentication bypass used in the same attacks.

7.264% KEV
  • Ivanti Endpoint Manager Mobile (EPMM) 11.10.x before 11.10.0.3
  • Ivanti Endpoint Manager Mobile (EPMM) 11.9.x before 11.9.1.2
  • Ivanti Endpoint Manager Mobile (EPMM) 11.8.x before 11.8.1.2
largeon the order of tens of thousands of EPMM appliance deployments worldwide (exact internet-exposed count unknown)
Full article322 words · extracted from infosecurity-magazine.com · click to collapse

Security vendor Ivanti has released an update to its Avalanche mobile device management (MDM) product which fixes 22 vulnerabilities, 13 of which are rated critical.

Ivanti Avalanche is described by the vendor as an enterprise MDM solution capable of managing distributed deployments of more than 100,000 mobile devices – including anything from warehouse scanners to handheld tablets.

However, its Avalanche 6.4.2 release published this week includes fixes for 13 flaws rated with a CVSS score of 9.8. They are a mix of stack-based buffer overflow remote code execution (RCE) vulnerabilities, heap-based buffer overflow RCE and unauthenticated buffer overflows.

“An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result … [in] code execution,” Ivanti warned in an advisory.

“To address the security vulnerabilities listed …, it is highly recommended to download the Avalanche installer and update to the latest Avalanche 6.4.2. The installation will apply a fix for each CVE listed …. These vulnerabilities affect any older versions of Avalanche (confirmed back to 6.3.1 but likely any 6.X versions are affected).”

Read more on Ivanti patching: Ivanti Discloses Yet Another Critical Flaw

There’s no suggestion the vulnerabilities are currently being exploited in active attacks, but Ivanti MDM products have in the past been targeted by threat actors.

Over the summer, the vendor was forced to patch multiple zero-day vulnerabilities in its Ivanti Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core. CVE-2023-35078 and CVE-2023-35081 were exploited in a likely state-sponsored attacks against several Norwegian government ministries.

“Mobile device management (MDM) systems are attractive targets for threat actors because they provide elevated access to thousands of mobile devices, and APT actors have exploited a previous MobileIron vulnerability,” the US Cybersecurity and Infrastructure Security Agency (CISA) wrote in an advisory at the time.

Alongside the 13 critical-rated vulnerabilities, Ivanti fixed a further nine high and medium severity bugs with its Avalanche 6.4.2 release.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ivanti-customers-patch-13-critical/