ZeroHour
The Recordpublished ()ingested

Ivanti warns of second vulnerability used in attacks on Norway gov’t

criticalVulnerability exploited in the wildimportance 60CVE-2023-35081CVE-2023-35078

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-35078
Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) Exposes PII

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass (CWE-287) that allows a remote, unauthenticated attacker to access specific API paths on a vulnerable server. Because these endpoints require no credentials, any attacker who can reach the server can invoke them directly. Through these paths an attacker can read PII such as user names, phone numbers, and mobile device details, and can also make configuration changes, including installing software and modifying security profiles on enrolled devices, giving attackers a lever into the managed mobile fleet. Organizations running EPMM, typically enterprises and government agencies using it for mobile device management, are affected; exact affected version ranges should be taken from Ivanti's advisory. The flaw is actively exploited: it was added to CISA's KEV on 2023-07-25 with known ransomware use, EPSS is ~100%, while no public PoC or CVSS score is yet available.

Do: Apply Ivanti's patched EPMM releases per the vendor's instructions immediately, as patching or discontinuing use is the CISA KEV required action. Hunt for unauthenticated requests to the affected API paths, and review enrolled devices for unexpected software installs or modified security profiles, since ransomware operators are known to have used this flaw. Verify internet-exposed EPMM servers are prioritized for remediation and that managed-device configurations have not been tampered with.

9.8100% KEV ransomware PoC
  • Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core)
largetens of thousands of deployed EPMM instances (enterprise/government MDM), with several thousand internet-exposed
CVE-2023-35081
Authenticated Path Traversal in Ivanti Endpoint Manager Mobile (EPMM)

CVE-2023-35081 is a path traversal (CWE-22) vulnerability in Ivanti Endpoint Manager Mobile (EPMM), the on-premises mobile device management appliance formerly known as MobileIron Core. It is triggered when an authenticated administrator submits crafted path input, allowing the attacker to write arbitrary files onto the appliance outside intended directories. Because arbitrary files can be written to the appliance, the flaw can be leveraged to further compromise the device, and public reporting indicates it was used in real-world attacks alongside a previously disclosed EPMM authentication bypass. Organizations running EPMM 11.8.x, 11.9.x, or 11.10.x prior to the fixed builds are affected. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-31, attacks on Norwegian government entities have been reported, and no public PoC is known.

Do: Upgrade EPMM to 11.10.0.3, 11.9.1.2, or 11.8.1.2 for the 11.10.x, 11.9.x, and 11.8.x branches respectively, and treat this as urgent given the CISA KEV listing. Until patched, restrict internet-facing access to the EPMM appliance and review the device for unexpected or newly written files and other signs of compromise. Administrators should also confirm they are not exposed via chaining with the previously disclosed EPMM authentication bypass used in the same attacks.

7.264% KEV
  • Ivanti Endpoint Manager Mobile (EPMM) 11.10.x before 11.10.0.3
  • Ivanti Endpoint Manager Mobile (EPMM) 11.9.x before 11.9.1.2
  • Ivanti Endpoint Manager Mobile (EPMM) 11.8.x before 11.8.1.2
largeon the order of tens of thousands of EPMM appliance deployments worldwide (exact internet-exposed count unknown)
Full article414 words · extracted from therecord.media · click to collapse

A second vulnerability affecting mobile endpoint management software from IT giant Ivanti has been discovered, according to a new advisory from the company.

Ivanti released an advisory on Friday afternoon about CVE-2023-35081 – a zero-day vulnerability that is different from the one hackers used to compromise a dozen Norwegian government agencies on Monday.

“A vulnerability has been discovered in Ivanti Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core. This vulnerability impacts all supported versions – releases 11.10, 11.9 and 11.8. Older versions/releases are also at risk. This vulnerability is different from CVE-2023-35078, released on July 23,” the company said.

“As of now we are only aware of the same limited number of customers impacted by CVE-2023-35078 as being impacted by CVE-2023-35081.”

The advisory says the vulnerability allows a threat actor to take a variety of actions on a victim device and can be used in conjunction with the first bug to bypass administrator authentication.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published its own warning about the advisory, urging customers of the company to immediately patch their devices due to the exploitation of both vulnerabilities.

CISA added CVE-2023-35078 to its Known Exploited Vulnerabilities catalog on Tuesday following confirmation by Norway’s government that it was used in the attacks on several agencies.

“This vulnerability was unique, and was discovered for the very first time here in Norway,” said Sofie Nystrøm, director of Norway’s National Security Agency. “If we had released the information about the vulnerability too early, it could have contributed to it being misused elsewhere in Norway and in the rest of the world.”

EPMM is used widely across multiple governments including in the U.S and a search on the security platform Shodan showed dozens of agencies in the U.S. and Europe potentially exposed to the issue among thousands of other potential victims.

According to CISA, the vulnerability could allow hackers to remotely access victims’ personally identifiable information, such as names, phone numbers, and other mobile device details.

An attacker can also make other configuration changes, including creating an administrative account that can make further changes to a vulnerable system, CISA said Monday in a security alert.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/ivanti-warns-of-second-vulnerability-norway-government-attack