Two Ivanti Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-35078 | Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) Exposes PII Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass (CWE-287) that allows a remote, unauthenticated attacker to access specific API paths on a vulnerable server. Because these endpoints require no credentials, any attacker who can reach the server can invoke them directly. Through these paths an attacker can read PII such as user names, phone numbers, and mobile device details, and can also make configuration changes, including installing software and modifying security profiles on enrolled devices, giving attackers a lever into the managed mobile fleet. Organizations running EPMM, typically enterprises and government agencies using it for mobile device management, are affected; exact affected version ranges should be taken from Ivanti's advisory. The flaw is actively exploited: it was added to CISA's KEV on 2023-07-25 with known ransomware use, EPSS is ~100%, while no public PoC or CVSS score is yet available. Do: Apply Ivanti's patched EPMM releases per the vendor's instructions immediately, as patching or discontinuing use is the CISA KEV required action. Hunt for unauthenticated requests to the affected API paths, and review enrolled devices for unexpected software installs or modified security profiles, since ransomware operators are known to have used this flaw. Verify internet-exposed EPMM servers are prioritized for remediation and that managed-device configurations have not been tampered with. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of deployed EPMM instances (enterprise/government MDM), with several thousand internet-exposed | |
| CVE-2023-35081 | Authenticated Path Traversal in Ivanti Endpoint Manager Mobile (EPMM) CVE-2023-35081 is a path traversal (CWE-22) vulnerability in Ivanti Endpoint Manager Mobile (EPMM), the on-premises mobile device management appliance formerly known as MobileIron Core. It is triggered when an authenticated administrator submits crafted path input, allowing the attacker to write arbitrary files onto the appliance outside intended directories. Because arbitrary files can be written to the appliance, the flaw can be leveraged to further compromise the device, and public reporting indicates it was used in real-world attacks alongside a previously disclosed EPMM authentication bypass. Organizations running EPMM 11.8.x, 11.9.x, or 11.10.x prior to the fixed builds are affected. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-31, attacks on Norwegian government entities have been reported, and no public PoC is known. Do: Upgrade EPMM to 11.10.0.3, 11.9.1.2, or 11.8.1.2 for the 11.10.x, 11.9.x, and 11.8.x branches respectively, and treat this as urgent given the CISA KEV listing. Until patched, restrict internet-facing access to the EPMM appliance and review the device for unexpected or newly written files and other signs of compromise. Administrators should also confirm they are not exposed via chaining with the previously disclosed EPMM authentication bypass used in the same attacks. | 7.2 | 64% | KEV |
| largeon the order of tens of thousands of EPMM appliance deployments worldwide (exact internet-exposed count unknown) | |
| CVE-2024-21887 +1 in the same advisory: …46805 | Command Injection RCE in Ivanti Connect Secure and Policy Secure Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available. Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories. | 9.1 group max | 100% | KEV ransomware PoC |
| largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher) |
Full article749 words · extracted from infosecurity-magazine.com · click to collapse
Ivanti customers have been urged to follow the security vendor’s suggested workaround after it confirmed that two zero-day vulnerabilities in its Connect Secure and Policy Secure gateways are being actively exploited.
Connect Secure is a VPN product while Policy Secure is a network access control (NAC) solution.
Security vendor Volexity yesterday claimed that a Chinese state actor tracked as UTA0178 was behind the attacks. It said the group may have been exploiting CVE-2023-46805 and CVE-2024-21887 as far back as December 3 2023 to place webshells on victim organizations’ internal and external-facing web servers.
The zero-day vulnerabilities affect all supported versions of Ivanti Connect Secure (ICS), formerly known as Pulse Connect Secure, and Ivanti Policy Secure gateways.
CVE-2023-46805 is an authentication bypass vulnerability in the web component of the two products that allows remote attackers to access restricted resources by bypassing control checks, Ivanti said in an advisory. It has a CVSS score of 8.2.
CVE-2024-21887 is a command injection vulnerability in the web components of the products which allows an authenticated administrator to send specially crafted requests that execute arbitrary commands on the appliance. It can be exploited over the internet and is given a CVSS score of 9.1.
The two can be chained to potentially devastating effects.
“If CVE-2024-21887 is used in conjunction with CVE-2023-46805, exploitation does not require authentication and enables a threat actor to craft malicious requests and execute arbitrary commands on the system,” Ivanti warned.
Action1 president and co-founder, Mike Walters, claimed that a Shodan search reveals around 15,000 Ivanti devices currently exposed online.
“Exploitation can lead to arbitrary command execution, MFA bypass, and potentially full system compromise,” he explained. “Organizations that have not yet applied available mitigations and those lacking proper security measures like firewalls and intrusion detection systems are likely to experience the most severe consequences.”
Read more: A Guide to Zero-Day Vulnerabilities and Exploits for the Uninitiated
Five Malware Families Associated with the Campaign
Google-owned Mandiant also identified advanced persistent threat (APT) groups currently exploiting the vulnerabilities, although the firm has not yet attributed the malicious activity to any specific group, Charles Carmakal, Mandiant Consulting CTO at Google Cloud, told Infosecurity.
The firm revealed that the threat actor was using five different malware families to conduct its exploitation campaign: The Zipline passive backdoor, the Thinspool dropper, the Lightwire and Wirefire webshells and the Warpwire credential harvester.
“These tools allow the threat actors to circumvent authentication and provide backdoor access to these devices,” the report said.
Patches Not Yet Available
Ivanti said it is aware of “less than 10 customers” impacted by these exploits, although it cautioned that the situation is still evolving.
“We have seen evidence of threat actors attempting to manipulate Ivanti’s internal integrity checker (ICT). Out of an abundance of caution, we are recommending that all customers run the external ICT,” it said.
“We have added new functionality to the external ICT that will be incorporated into the internal ICT in the future. We regularly provide updates to the external and internal ICT, so customers should always ensure they are running the latest version of each.”
Patches will not be available until the week of January 22, and even then Ivanti is releasing them in a staggered schedule according to product version. In the meantime, it has released a series of mitigation steps that customers are urged to follow immediately.
“It is crucial for organizations to take immediate action by importing the available mitigation release from Ivanti’s download portal,” said Walters. “The clock is ticking.”
Mandiant’s Carmakal confirmed the number of identified victims.
“The known zero-day exploitation was performed by a single threat group, but it’s probable that other threat actors will be able to develop exploit code and exploit it for a variety of motivations. We implore organizations to run the new integrity checker tool provided by Ivanti to assess if their device was compromised already [and] we urge them to deploy the mitigations that Ivanti published ASAP," he told Infosecurity.
Ivanti Products' Vulnerabilities Exploited in the Past
Ivanti products have previously been exploited by suspected Chinese state hackers. In July, they targeted CVE-2023-35078 and CVE-2023-35081 in the firm’s Endpoint Manager Mobile (EPMM) product to compromise several Norwegian government agencies.
Read more about Ivanti vulnerabilities: Ivanti Patches Zero-Day Bug Used in Norway Attacks
In April 2021, prior to Ivanti’s acquisition of Pulse Secure, Chinese hackers exploited another critical zero-day bug in the Pulse Connect Secure product.
Updated on January 15, 2024. Additional reporting by Kevin Poireault.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/two-ivanti-zerodays-actively/