ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds Ivanti EPMM flaw to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-35078

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-35078
Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) Exposes PII

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass (CWE-287) that allows a remote, unauthenticated attacker to access specific API paths on a vulnerable server. Because these endpoints require no credentials, any attacker who can reach the server can invoke them directly. Through these paths an attacker can read PII such as user names, phone numbers, and mobile device details, and can also make configuration changes, including installing software and modifying security profiles on enrolled devices, giving attackers a lever into the managed mobile fleet. Organizations running EPMM, typically enterprises and government agencies using it for mobile device management, are affected; exact affected version ranges should be taken from Ivanti's advisory. The flaw is actively exploited: it was added to CISA's KEV on 2023-07-25 with known ransomware use, EPSS is ~100%, while no public PoC or CVSS score is yet available.

Do: Apply Ivanti's patched EPMM releases per the vendor's instructions immediately, as patching or discontinuing use is the CISA KEV required action. Hunt for unauthenticated requests to the affected API paths, and review enrolled devices for unexpected software installs or modified security profiles, since ransomware operators are known to have used this flaw. Verify internet-exposed EPMM servers are prioritized for remediation and that managed-device configurations have not been tampered with.

9.8100% KEV ransomware PoC
  • Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core)
largetens of thousands of deployed EPMM instances (enterprise/government MDM), with several thousand internet-exposed

Indicators of compromiseAll →

TypeIndicatorContext
ipv411.10.0.2this week with the release of EPMM 11.8.1.1, 11.9.1.1, and 11.10.0.2 patches. Ivanti confirmed that the vulnerability is critica
ipv411.8.1.1giant addressed the flaw this week with the release of EPMM 11.8.1.1, 11.9.1.1, and 11.10.0.2 patches. Ivanti confirmed that the
ipv411.9.1.1essed the flaw this week with the release of EPMM 11.8.1.1, 11.9.1.1, and 11.10.0.2 patches. Ivanti confirmed that the vulnerabi
Full article358 words · extracted from securityaffairs.com · click to collapse

US CISA added actively exploited Ivanti ‘s Endpoint Manager Mobile (EPMM) vulnerability to its Known Exploited Vulnerabilities catalog.

US Cybersecurity and Infrastructure Security Agency (CISA) added actively exploited Ivanti ‘s Endpoint Manager Mobile (EPMM) vulnerability, tracked as CVE-2023-35078, to its Known Exploited Vulnerabilities Catalog.

The vulnerability is an authentication bypass issue impacting Ivanti Endpoint Manager Mobile (EPMM) mobile device management software (formerly MobileIron Core).

An unauthorized user can exploit the flaw to access restricted functionality or resources of the application without proper authentication.

“If exploited, this vulnerability enables an unauthorized, remote (internet-facing) actor to potentially access users’ personally identifiable information and make limited changes to the server.” reads the advisory published by the software firm. “We have received information from a credible source indicating exploitation has occurred. We continue to work with our customers and partners to investigate this situation.”

This vulnerability impacts all supported versions (Version 11.4 releases 11.10, 11.9 and 11.8), but the company pointed out that older versions/releases are also at risk.

The IT software giant addressed the flaw this week with the release of EPMM 11.8.1.1, 11.9.1.1, and 11.10.0.2 patches.

Ivanti confirmed that the vulnerability is critical and urges customers to immediately address it.

“It’s a serious zero day vulnerability which is very easy to exploit, where Ivanti are trying to hide it for some reason – this will get mass internet swept. I’d strongly recommend upgrading, and if you can’t get off EOL, switch off the appliance.” wrote the popular researchers Kevin Beaumont on Mastodon.

The zero-day vulnerability was exploited by threat actors in recent attacks against the ICT platform used by twelve ministries of the Norwegian government.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this flaw by August 15, 2023.

Follow me on Twitter: @securityaffairs Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Ivanti)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/148830/hacking/cisa-ivanti-epmm-flaw-catalog.html