ZeroHour
Security Affairspublished ()ingested @securityaffairs

Ivanti fixed a critical EPM flaw that can result in RCE

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-35078
Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) Exposes PII

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass (CWE-287) that allows a remote, unauthenticated attacker to access specific API paths on a vulnerable server. Because these endpoints require no credentials, any attacker who can reach the server can invoke them directly. Through these paths an attacker can read PII such as user names, phone numbers, and mobile device details, and can also make configuration changes, including installing software and modifying security profiles on enrolled devices, giving attackers a lever into the managed mobile fleet. Organizations running EPMM, typically enterprises and government agencies using it for mobile device management, are affected; exact affected version ranges should be taken from Ivanti's advisory. The flaw is actively exploited: it was added to CISA's KEV on 2023-07-25 with known ransomware use, EPSS is ~100%, while no public PoC or CVSS score is yet available.

Do: Apply Ivanti's patched EPMM releases per the vendor's instructions immediately, as patching or discontinuing use is the CISA KEV required action. Hunt for unauthenticated requests to the affected API paths, and review enrolled devices for unexpected software installs or modified security profiles, since ransomware operators are known to have used this flaw. Verify internet-exposed EPMM servers are prioritized for remediation and that managed-device configurations have not been tampered with.

9.8100% KEV ransomware PoC
  • Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core)
largetens of thousands of deployed EPMM instances (enterprise/government MDM), with several thousand internet-exposed
CVE-2023-35082
Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core

Ivanti Endpoint Manager Mobile (EPMM) and its predecessor MobileIron Core contain an improper authentication flaw (CWE-287) that allows an unauthorized user to bypass authentication and access restricted functionality or resources of the application. It is triggered by sending unauthenticated requests to the affected appliance, with no valid credentials or user interaction required. A successful attacker gains access to protected MDM functionality and resources on the server, which has been leveraged in broader intrusions, including ransomware operations. Any organization running EPMM or MobileIron Core, particularly with the management interface exposed to the internet, is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-18 with known ransomware use, and EPSS assigns it a ~100% probability of exploitation within 30 days (100th percentile).

Do: Apply Ivanti's patched releases immediately per the vendor advisory, or discontinue use if mitigations are unavailable, as required by CISA's KEV listing. Because the flaw has known ransomware use, review EPMM/MobileIron Core logs for unauthenticated access to restricted functionality and hunt for signs of follow-on compromise. Prioritize patching internet-facing instances and limit exposure of the management interface until updates are applied.

9.8100% KEV ransomware
  • Ivanti Endpoint Manager Mobile (EPMM)
  • Ivanti MobileIron Core
largetens of thousands of enterprise and government deployments, with only a few thousand servers directly internet-exposed
CVE-2023-38035
Authentication Bypass in Ivanti Sentry (MobileIron Sentry) Admin Interface

Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass (CWE-863) caused by an insufficiently restrictive Apache HTTPD configuration on the product's administrative interface. An attacker triggers the flaw by sending crafted HTTP requests to the administrative interface, which the permissive web server configuration serves without properly enforcing authentication controls. Successful exploitation grants unauthenticated administrative access to the Sentry management interface, giving attackers a foothold in the MDM infrastructure. Any organization running Ivanti Sentry is affected, with risk highest where the administrative interface is reachable from the internet. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-08-22 with known ransomware use, and EPSS currently rates the 30-day exploitation probability at 100% (percentile 100) even though no public PoC is known.

Do: Apply the mitigations prescribed in Ivanti's security advisory, including the corrective Apache HTTPD configuration and any patched Sentry release the vendor directs you to, or discontinue use of the product if mitigations are unavailable per the CISA KEV required action. Restrict or remove internet exposure of the Sentry administrative interface and review access logs for unauthenticated requests to the admin interface indicating attempted or successful exploitation.

9.8100% KEV ransomware PoC
  • Ivanti Sentry (formerly MobileIron Sentry)
moderateroughly 1,000-10,000 internet-exposed Ivanti Sentry deployments (on the order of a few thousand)
CVE-2023-39336
An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to exec

An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this may also lead to RCE on the core server.

NVD description · AI analysis pending
8.810%
  • ivanti endpoint manager
Full article324 words · extracted from securityaffairs.com · click to collapse

Ivanti fixed a critical vulnerability in its Endpoint Manager (EPM) solution that could lead to remote code execution (RCE) on vulnerable servers

Ivanti has released security updates to address a critical vulnerability, tracked as CVE-2023-39336 (CVSS score 9.6), impacting its Endpoint Manager (EPM) solution. The exploitation of this vulnerability could lead to remote code execution (RCE) on vulnerable servers.

“If exploited, an attacker with access to the internal network can leverage an unspecified SQL injection to execute arbitrary SQL queries and retrieve output without the need for authentication.” reads the advisory published by company. “This can then allow the attacker control over machines running the EPM agent. When the core server is configured to use SQL express, this might lead to RCE on the core server”

The vulnerability impacts EPM 2021 and EPM 2022 prior to SU5.

At the end of July, Ivanti disclosed another security vulnerability impacting Endpoint Manager Mobile (EPMM), tracked as  CVE-2023-35078 (CVSS score: 7.8), that was exploited in the wild as part of an exploit chain by threat actors.

In early August, Rapid7 researchers discovered a bypass for the above vulnerability in Ivanti Endpoint Manager Mobile (EPMM).

The new vulnerability, tracked as CVE-2023-35082 (CVSS score: 10.0), can be exploited by unauthenticated attackers to access the API in older unsupported versions of MobileIron Core (11.2 and below). Ivanti addressed the vulnerability with the release of the MobileIron Core 11.3 version

In August, the software giant released urgent security patches to address the critical severity vulnerability CVE-2023-38035 impacting the Ivanti Sentry (formerly MobileIron Sentry) product.

The vulnerability could be exploited to access sensitive API data and configurations, run system commands, or write files onto the system. The vulnerability CVE-2023-38035 impacts Sentry versions 9.18 and prior.

The researchers at cybersecurity firm Horizon3 have published a technical analysis for this vulnerability and a proof-of-concept (PoC) exploit.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Ivanti EPM)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/156951/security/ivanti-critical-epm-flaw.html