All versions of Ivanti product affected by vulnerability used in Norway gov’t attack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-35078 | Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) Exposes PII Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass (CWE-287) that allows a remote, unauthenticated attacker to access specific API paths on a vulnerable server. Because these endpoints require no credentials, any attacker who can reach the server can invoke them directly. Through these paths an attacker can read PII such as user names, phone numbers, and mobile device details, and can also make configuration changes, including installing software and modifying security profiles on enrolled devices, giving attackers a lever into the managed mobile fleet. Organizations running EPMM, typically enterprises and government agencies using it for mobile device management, are affected; exact affected version ranges should be taken from Ivanti's advisory. The flaw is actively exploited: it was added to CISA's KEV on 2023-07-25 with known ransomware use, EPSS is ~100%, while no public PoC or CVSS score is yet available. Do: Apply Ivanti's patched EPMM releases per the vendor's instructions immediately, as patching or discontinuing use is the CISA KEV required action. Hunt for unauthenticated requests to the affected API paths, and review enrolled devices for unexpected software installs or modified security profiles, since ransomware operators are known to have used this flaw. Verify internet-exposed EPMM servers are prioritized for remediation and that managed-device configurations have not been tampered with. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of deployed EPMM instances (enterprise/government MDM), with several thousand internet-exposed | |
| CVE-2023-35082 | Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Ivanti Endpoint Manager Mobile (EPMM) and its predecessor MobileIron Core contain an improper authentication flaw (CWE-287) that allows an unauthorized user to bypass authentication and access restricted functionality or resources of the application. It is triggered by sending unauthenticated requests to the affected appliance, with no valid credentials or user interaction required. A successful attacker gains access to protected MDM functionality and resources on the server, which has been leveraged in broader intrusions, including ransomware operations. Any organization running EPMM or MobileIron Core, particularly with the management interface exposed to the internet, is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-18 with known ransomware use, and EPSS assigns it a ~100% probability of exploitation within 30 days (100th percentile). Do: Apply Ivanti's patched releases immediately per the vendor advisory, or discontinue use if mitigations are unavailable, as required by CISA's KEV listing. Because the flaw has known ransomware use, review EPMM/MobileIron Core logs for unauthenticated access to restricted functionality and hunt for signs of follow-on compromise. Prioritize patching internet-facing instances and limit exposure of the management interface until updates are applied. | 9.8 | 100% | KEV ransomware |
| largetens of thousands of enterprise and government deployments, with only a few thousand servers directly internet-exposed |
Full article413 words · extracted from therecord.media · click to collapse
IT giant Ivanti said on Monday that several recently-discovered vulnerabilities affect all versions of their Endpoint Manager Mobile (EPMM) tool. EPMM, formerly MobileIron Core, is a platform that allows organizations to manage mobile devices like phones and tablets as well as enforce content and application policies. Two weeks ago, the government of Norway revealed that 12 government agencies in the country had been hacked through several zero-days affecting EPMM. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Norway’s government published an advisory about the vulnerabilities last week, noting that nation state hackers had been exploiting them since April. But just two days after that advisory, Ivanti announced a third issue: CVE-2023-35082. The vulnerability “enables an unauthorized, remote (internet-facing) actor to potentially access users’ personally identifiable information and make limited changes to the server,” they explained, noting it has a CVSS score of 10 — the highest level of severity for a vulnerability. Ivanti initially said the bug only affected MobileIron Core 11.2 and earlier. But in an updated advisory on Monday, the company said the vulnerability affects all versions. “Since originally reporting CVE-2023-35082… Ivanti has continued its investigation and has found that this vulnerability impacts all versions of Ivanti Endpoint Manager Mobile 11.10, 11.9 and 11.8 and MobileIron Core 11.7 and below,” the company said. “The risk of exploitation depends on the individual customer’s configurations. This vulnerability only impacts EPMM / MobileIron Core. No other Ivanti products are affected. Ivanti has an RPM Fix for versions 11.10 to 11.3 available now. Customers on older versions should first upgrade to 11.10 and then apply the RPM fix.” The bug was discovered by Stephen Fewer, principal security researcher at security firm Rapid7, while examining CVE-2023-35078, the first issue found affecting Ivanti’s EPMM product. MobileIron was originally its own company before being bought by Ivanti in 2020 and rebranded as EPMM According to searches on the security website Shodan, thousands of organizations are still exposed to the Ivanti vulnerabilities, many of which are located in the U.S. CISA added the first two bugs to its catalog of Known Exploited Vulnerabilities, giving federal civilian agencies until August 21 to patch it.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/all-ivanti-versions-affected-by-vulnerability-tied-to-norway-attacks