CISA in New Warning Over Ivanti Vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-35078 | Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) Exposes PII Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass (CWE-287) that allows a remote, unauthenticated attacker to access specific API paths on a vulnerable server. Because these endpoints require no credentials, any attacker who can reach the server can invoke them directly. Through these paths an attacker can read PII such as user names, phone numbers, and mobile device details, and can also make configuration changes, including installing software and modifying security profiles on enrolled devices, giving attackers a lever into the managed mobile fleet. Organizations running EPMM, typically enterprises and government agencies using it for mobile device management, are affected; exact affected version ranges should be taken from Ivanti's advisory. The flaw is actively exploited: it was added to CISA's KEV on 2023-07-25 with known ransomware use, EPSS is ~100%, while no public PoC or CVSS score is yet available. Do: Apply Ivanti's patched EPMM releases per the vendor's instructions immediately, as patching or discontinuing use is the CISA KEV required action. Hunt for unauthenticated requests to the affected API paths, and review enrolled devices for unexpected software installs or modified security profiles, since ransomware operators are known to have used this flaw. Verify internet-exposed EPMM servers are prioritized for remediation and that managed-device configurations have not been tampered with. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of deployed EPMM instances (enterprise/government MDM), with several thousand internet-exposed | |
| CVE-2023-35081 | Authenticated Path Traversal in Ivanti Endpoint Manager Mobile (EPMM) CVE-2023-35081 is a path traversal (CWE-22) vulnerability in Ivanti Endpoint Manager Mobile (EPMM), the on-premises mobile device management appliance formerly known as MobileIron Core. It is triggered when an authenticated administrator submits crafted path input, allowing the attacker to write arbitrary files onto the appliance outside intended directories. Because arbitrary files can be written to the appliance, the flaw can be leveraged to further compromise the device, and public reporting indicates it was used in real-world attacks alongside a previously disclosed EPMM authentication bypass. Organizations running EPMM 11.8.x, 11.9.x, or 11.10.x prior to the fixed builds are affected. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-31, attacks on Norwegian government entities have been reported, and no public PoC is known. Do: Upgrade EPMM to 11.10.0.3, 11.9.1.2, or 11.8.1.2 for the 11.10.x, 11.9.x, and 11.8.x branches respectively, and treat this as urgent given the CISA KEV listing. Until patched, restrict internet-facing access to the EPMM appliance and review the device for unexpected or newly written files and other signs of compromise. Administrators should also confirm they are not exposed via chaining with the previously disclosed EPMM authentication bypass used in the same attacks. | 7.2 | 64% | KEV |
| largeon the order of tens of thousands of EPMM appliance deployments worldwide (exact internet-exposed count unknown) |
Full article322 words · extracted from infosecurity-magazine.com · click to collapse
US and Norwegian security agencies have released a new security advisory warning that APT actors may be combining exploits for two Ivanti vulnerabilities in attacks.
Security vendor Ivanti was forced to patch zero-day vulnerability CVE-2023-35078 on July 23 after reports it had been used in a sophisticated attack on the Norwegian government that compromised 12 ministries.
Read more on the Ivanti flaw: Cyber-Attack Strikes Norwegian Government Ministries
However, the firm patched a second bug, CVE-2023-35081, on July 28 after the Norwegian National Cyber Security Centre (NCSC-NO) observed possible chaining of the two in attacks, explained the US Cybersecurity and Infrastructure Security Agency (CISA).
“CVE-2023-35078 is a critical vulnerability affecting Ivanti Endpoint Manager Mobile (EPMM) (formerly known as MobileIron Core). The vulnerability allows threat actors to access personally identifiable information (PII) and gain the ability to make configuration changes on compromised systems,” the new CISA advisory explained.
“CVE-2023-35081 enables actors with EPMM administrator privileges to write arbitrary files with the operating system privileges of the EPMM web application server. Threat actors can chain these vulnerabilities to gain initial, privileged access to EPMM systems and execute uploaded files, such as webshells.”
CISA has already listed both bugs in its Known Exploited Vulnerabilities Catalog, meaning civilian federal agencies have until August 15 to patch CVE-2023-35078 and August 21 to patch CVE-2023-35081.
There’s no clarity at this stage on whether the two were definitely used in the Norwegian attacks. CISA said only that CVE-2023-35078 was exploited from April to July by APT attackers to harvest information from the government in Oslo.
“Mobile device management (MDM) systems are attractive targets for threat actors because they provide elevated access to thousands of mobile devices, and APT actors have exploited a previous MobileIron vulnerability,” noted the advisory.
“Consequently, CISA and NCSC-NO are concerned about the potential for widespread exploitation in government and private sector networks.”
Editorial image credit: Alexander Tolstykh / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-in-new-warning-ivanti/