Ivanti urges customers to apply patch for exploited MobileIron vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-35078 | Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) Exposes PII Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass (CWE-287) that allows a remote, unauthenticated attacker to access specific API paths on a vulnerable server. Because these endpoints require no credentials, any attacker who can reach the server can invoke them directly. Through these paths an attacker can read PII such as user names, phone numbers, and mobile device details, and can also make configuration changes, including installing software and modifying security profiles on enrolled devices, giving attackers a lever into the managed mobile fleet. Organizations running EPMM, typically enterprises and government agencies using it for mobile device management, are affected; exact affected version ranges should be taken from Ivanti's advisory. The flaw is actively exploited: it was added to CISA's KEV on 2023-07-25 with known ransomware use, EPSS is ~100%, while no public PoC or CVSS score is yet available. Do: Apply Ivanti's patched EPMM releases per the vendor's instructions immediately, as patching or discontinuing use is the CISA KEV required action. Hunt for unauthenticated requests to the affected API paths, and review enrolled devices for unexpected software installs or modified security profiles, since ransomware operators are known to have used this flaw. Verify internet-exposed EPMM servers are prioritized for remediation and that managed-device configurations have not been tampered with. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of deployed EPMM instances (enterprise/government MDM), with several thousand internet-exposed |
Full article274 words · extracted from therecord.media · click to collapse
The IT giant Ivanti is urging customers to apply a patch for a vulnerability in a product used by dozens of governments around the world. An Ivanti spokesperson told Recorded Future News that it recently became aware of a vulnerability impacting its Endpoint Manager Mobile customers. The product was formerly called MobileIron Core before it was purchased by Ivanti in 2020. Concerns about the vulnerability, tracked as CVE-2023-35078, grew after several cybersecurity experts warned that the zero day was being exploited. The issue affects versions 11.10, 11.9 and 11.8, as well as older end-of-life installations of the program. Patches have been released for 11.8.1.1, 11.9.1.1 and 11.10.0.2. “We immediately developed and released a patch and are actively engaging with customers to help them apply the fix. Our customers’ security is our top priority,” Ivanti said, arguing that it is “practicing responsible disclosure protocols.” The company did not respond to several questions about the issue and the remediation process, which has drawn criticism for being confusing after they initially took down a public advisory about the issue. The company has declined to publish a public advisory for the issue, instead putting it behind a paywall. While the company did not say publicly if the bug has been exploited, in the private advisory only available to Ivanti customers it said it has been used in attacks on customers. Endpoint Manager Mobile is used widely among governments across the world, and a search on the security platform Shodan showed dozens of agencies in the U.S. and Europe potentially exposed to the issue. The issue was first reported by the German news outlet Heise and BleepingComputer.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/ivanti-urges-customers-to-apply-patch