ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Ivanti Warns of Critical Zero-Day Flaw Being Actively Exploited in Sentry Software

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27532
Missing Authentication in Veeam Backup & Replication Exposes Stored Credentials

Veeam Backup & Replication (VBR) contains a missing-authentication flaw (CWE-306) in its Cloud Connect component that lets an unauthenticated network attacker obtain encrypted credentials stored in VBR's configuration database. It is triggered simply by connecting to the exposed service, because the function that serves credential material performs no authentication check; no privileges or user interaction are required (CVSS 3.1: 7.5, network vector). With the recovered credentials, an attacker can gain access to backup infrastructure hosts, which has been used as an entry point and pivot for ransomware operations. Any organization running Veeam Backup & Replication is potentially affected, with the greatest risk where the VBR/Cloud Connect service is reachable from the internet. Exploitation is confirmed: CISA added the bug to its KEV catalog on 2023-08-22 with known ransomware use, the Cuba ransomware group has been observed stealing credentials through this exploit, and EPSS assigns a 77.6% near-term exploitation probability (100th percentile).

Do: Apply the fixes Veeam provides in its security advisory immediately — per CISA's KEV listing, patch per vendor instructions or discontinue use — prioritizing internet-facing Cloud Connect servers. After patching, rotate all credentials stored in the configuration database, since they should be considered exposed, and review those accounts for signs of misuse. Restrict network access to the VBR service from untrusted networks and check servers for exploitation indicators such as unexpected connections to the service or anomalous logins with stored credentials.

7.578% KEV ransomware
  • Veeam Backup & Replication
largetens of thousands of deployments, of which thousands are internet-exposed (estimate)
CVE-2023-32560
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution.

An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.

NVD description · AI analysis pending
9.899%
  • ivanti avalanche
CVE-2023-35078
Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) Exposes PII

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass (CWE-287) that allows a remote, unauthenticated attacker to access specific API paths on a vulnerable server. Because these endpoints require no credentials, any attacker who can reach the server can invoke them directly. Through these paths an attacker can read PII such as user names, phone numbers, and mobile device details, and can also make configuration changes, including installing software and modifying security profiles on enrolled devices, giving attackers a lever into the managed mobile fleet. Organizations running EPMM, typically enterprises and government agencies using it for mobile device management, are affected; exact affected version ranges should be taken from Ivanti's advisory. The flaw is actively exploited: it was added to CISA's KEV on 2023-07-25 with known ransomware use, EPSS is ~100%, while no public PoC or CVSS score is yet available.

Do: Apply Ivanti's patched EPMM releases per the vendor's instructions immediately, as patching or discontinuing use is the CISA KEV required action. Hunt for unauthenticated requests to the affected API paths, and review enrolled devices for unexpected software installs or modified security profiles, since ransomware operators are known to have used this flaw. Verify internet-exposed EPMM servers are prioritized for remediation and that managed-device configurations have not been tampered with.

9.8100% KEV ransomware PoC
  • Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core)
largetens of thousands of deployed EPMM instances (enterprise/government MDM), with several thousand internet-exposed
CVE-2023-35081
Authenticated Path Traversal in Ivanti Endpoint Manager Mobile (EPMM)

CVE-2023-35081 is a path traversal (CWE-22) vulnerability in Ivanti Endpoint Manager Mobile (EPMM), the on-premises mobile device management appliance formerly known as MobileIron Core. It is triggered when an authenticated administrator submits crafted path input, allowing the attacker to write arbitrary files onto the appliance outside intended directories. Because arbitrary files can be written to the appliance, the flaw can be leveraged to further compromise the device, and public reporting indicates it was used in real-world attacks alongside a previously disclosed EPMM authentication bypass. Organizations running EPMM 11.8.x, 11.9.x, or 11.10.x prior to the fixed builds are affected. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-31, attacks on Norwegian government entities have been reported, and no public PoC is known.

Do: Upgrade EPMM to 11.10.0.3, 11.9.1.2, or 11.8.1.2 for the 11.10.x, 11.9.x, and 11.8.x branches respectively, and treat this as urgent given the CISA KEV listing. Until patched, restrict internet-facing access to the EPMM appliance and review the device for unexpected or newly written files and other signs of compromise. Administrators should also confirm they are not exposed via chaining with the previously disclosed EPMM authentication bypass used in the same attacks.

7.264% KEV
  • Ivanti Endpoint Manager Mobile (EPMM) 11.10.x before 11.10.0.3
  • Ivanti Endpoint Manager Mobile (EPMM) 11.9.x before 11.9.1.2
  • Ivanti Endpoint Manager Mobile (EPMM) 11.8.x before 11.8.1.2
largeon the order of tens of thousands of EPMM appliance deployments worldwide (exact internet-exposed count unknown)
CVE-2023-38035
Authentication Bypass in Ivanti Sentry (MobileIron Sentry) Admin Interface

Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass (CWE-863) caused by an insufficiently restrictive Apache HTTPD configuration on the product's administrative interface. An attacker triggers the flaw by sending crafted HTTP requests to the administrative interface, which the permissive web server configuration serves without properly enforcing authentication controls. Successful exploitation grants unauthenticated administrative access to the Sentry management interface, giving attackers a foothold in the MDM infrastructure. Any organization running Ivanti Sentry is affected, with risk highest where the administrative interface is reachable from the internet. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-08-22 with known ransomware use, and EPSS currently rates the 30-day exploitation probability at 100% (percentile 100) even though no public PoC is known.

Do: Apply the mitigations prescribed in Ivanti's security advisory, including the corrective Apache HTTPD configuration and any patched Sentry release the vendor directs you to, or discontinue use of the product if mitigations are unavailable per the CISA KEV required action. Restrict or remove internet exposure of the Sentry administrative interface and review access logs for unauthenticated requests to the admin interface indicating attempted or successful exploitation.

9.8100% KEV ransomware PoC
  • Ivanti Sentry (formerly MobileIron Sentry)
moderateroughly 1,000-10,000 internet-exposed Ivanti Sentry deployments (on the order of a few thousand)
Full article469 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 22, 2023Zero-Day / Software Security

Software services provider Ivanti is warning of a new critical zero-day flaw impacting Ivanti Sentry (formerly MobileIron Sentry) that it said is being actively exploited in the wild, marking an escalation of its security woes.

Tracked as CVE-2023-38035 (CVSS score: 9.8), the issue has been described as a case of authentication bypass impacting versions 9.18 and prior due to what it called an due to an insufficiently restrictive Apache HTTPD configuration.

"If exploited, this vulnerability enables an unauthenticated actor to access some sensitive APIs that are used to configure the Ivanti Sentry on the administrator portal (port 8443, commonly MICS)," the company said.

"While the issue has a high CVSS score, there is a low risk of exploitation for customers who do not expose port 8443 to the internet."

Successful exploitation of the bug could allow an attacker to change configuration, run system commands, or write files onto the system. It's recommended that users restrict access to MICS to internal management networks.

While exact details surrounding the nature of exploitation are currently unknown, the company said it's "only aware of a limited number of customers" who have been affected.

Norwegian cybersecurity company mnemonic has been credited with discovering and reporting the flaw.

"Successful exploitation allows an unauthenticated threat actor to read and write files to the Ivanti Sentry server and execute OS commands as system administrator (root) through use of 'super user do' (sudo)," it said.

What's more, CVE-2023-38035 could be weaponized after exploiting CVE-2023-35078 and CVE-2023-35081, two other recently disclosed flaws in the Ivanti Endpoint Manager Mobile (EPMM), in scenarios where port 8443 is not publicly accessible as the admin portal is used to communicate with the Ivanti EPMM server.

The development comes a week after Ivanti fixed two critical stack-based buffer overflow flaws (CVE-2023-32560) in its Avalanche software that could lead to crashes and arbitrary code execution on vulnerable installations.

Update

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added CVE-2023-38035 to its its Known Exploited Vulnerabilities (KEV) catalog, alongside CVE-2023-27532, a critical bug in Veeam Backup & Replication software, following active in-the-wild exploitation.

Federal Civilian Executive Branch (FCEB) agencies are required to apply the patches by September 12, 2023, to secure their networks against possible cyber attacks.

PoC for the Flaw Now Available

Horizon3.ai has published a proof-of-concept (PoC) for CVE-2023-38035, making it imperative that enterprises prioritize applying the patch. The cybersecurity firm said it identified over 500 MobileIron Sentry instances that are exposed to the internet as of August 24, 2023, most of which are from Germany, the U.S., the U.K., China, and France.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/08/ivanti-warns-of-critical-zero-day-flaw.html