ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Ivanti EPMM and MobileIron Core vulnerability is actively exploited, CISA confirms (CVE-2023-35082)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-35078
Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) Exposes PII

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass (CWE-287) that allows a remote, unauthenticated attacker to access specific API paths on a vulnerable server. Because these endpoints require no credentials, any attacker who can reach the server can invoke them directly. Through these paths an attacker can read PII such as user names, phone numbers, and mobile device details, and can also make configuration changes, including installing software and modifying security profiles on enrolled devices, giving attackers a lever into the managed mobile fleet. Organizations running EPMM, typically enterprises and government agencies using it for mobile device management, are affected; exact affected version ranges should be taken from Ivanti's advisory. The flaw is actively exploited: it was added to CISA's KEV on 2023-07-25 with known ransomware use, EPSS is ~100%, while no public PoC or CVSS score is yet available.

Do: Apply Ivanti's patched EPMM releases per the vendor's instructions immediately, as patching or discontinuing use is the CISA KEV required action. Hunt for unauthenticated requests to the affected API paths, and review enrolled devices for unexpected software installs or modified security profiles, since ransomware operators are known to have used this flaw. Verify internet-exposed EPMM servers are prioritized for remediation and that managed-device configurations have not been tampered with.

9.8100% KEV ransomware PoC
  • Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core)
largetens of thousands of deployed EPMM instances (enterprise/government MDM), with several thousand internet-exposed
CVE-2023-35082
Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core

Ivanti Endpoint Manager Mobile (EPMM) and its predecessor MobileIron Core contain an improper authentication flaw (CWE-287) that allows an unauthorized user to bypass authentication and access restricted functionality or resources of the application. It is triggered by sending unauthenticated requests to the affected appliance, with no valid credentials or user interaction required. A successful attacker gains access to protected MDM functionality and resources on the server, which has been leveraged in broader intrusions, including ransomware operations. Any organization running EPMM or MobileIron Core, particularly with the management interface exposed to the internet, is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-18 with known ransomware use, and EPSS assigns it a ~100% probability of exploitation within 30 days (100th percentile).

Do: Apply Ivanti's patched releases immediately per the vendor advisory, or discontinue use if mitigations are unavailable, as required by CISA's KEV listing. Because the flaw has known ransomware use, review EPMM/MobileIron Core logs for unauthenticated access to restricted functionality and hunt for signs of follow-on compromise. Prioritize patching internet-facing instances and limit exposure of the management interface until updates are applied.

9.8100% KEV ransomware
  • Ivanti Endpoint Manager Mobile (EPMM)
  • Ivanti MobileIron Core
largetens of thousands of enterprise and government deployments, with only a few thousand servers directly internet-exposed
CVE-2024-21887
+1 in the same advisory: …46805
Command Injection RCE in Ivanti Connect Secure and Policy Secure

Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available.

Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories.

9.1
group max
100% KEV ransomware PoC
  • Ivanti Connect Secure (ICS, formerly Pulse Connect Secure)
  • Ivanti Policy Secure
largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher)
Full article396 words · extracted from helpnetsecurity.com · click to collapse

A previously patched critical vulnerability (CVE-2023-35082) affecting Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core is being actively exploited, the Cybersecurity and Infrastructure Security Agency (CISA) has confirmed by adding the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV).

exploited CVE-2023-35082

It is not known whether the vulnerability is being exploited by ransomware groups, and CISA does not publish specific information about attacks in which the vulnerabilities in the KEV catalog are exploited.

But it does seem that at least in this case, the inclusion comes rather late: Ivanti’s Knowledge Base entry for CVE-2023-35082 – which has apparently last been updated on August 22, 2023 – states in the FAQ section that “Ivanti has been informed of exploitation by a few customers who have been exploited since the details were made publicly available by Rapid7.”

Ivanti’s security advisory for CVE-2023-35082 still doesn’t mention active exploitation, though it has a link to the aforementioned Knowledge Base article (the link has been added as part of an update of the advisory made on August 21, 2023).

CVE-2023-35082 has been fixed

CVE-2023-35082 is a remote unauthenticated API access vulnerability that can be exploited by unauthorized, remote (internet-facing) threat actors to obtain users’ personally identifiable information (PII) and make alterations to the server.

The flaw was discovered and reported by Rapid7 in early August, 2023, and they consider it to be a patch bypass for CVE-2023-35078, another authentication bypass vulnerability in Ivanti EPMM.

CVE-2023-35082 was initially believed to affect only MobileIron Core versions 11.2 and prior, but Ivanti soon confirmed that it affects all versions of Ivanti Endpoint Manager Mobile (EPMM) 11.10, 11.9 and 11.8 and MobileIron Core 11.7 and below. “The risk of exploitation depends on the individual customer’s configurations,” the company noted.

Ivanti first provided an RPM script for versions 11.10 to 11.3 as a temporary mitigation, and later included a fix in EPMM v11.11.

Customers who haven’t yet upgraded to v11.11 (or later) should do so quickly. They should also search for indicators of compromise provided by Rapid7, to check whether they’ve been breached through this vulnerability.

Other Ivanti offerings under attack

Ivanti has recently disclosed two zero-days affecting its Connect Secure VPN devices that are also being exploited by attackers.

CVE-2023-46805, an authentication bypass vulnerability, and CVE-2024-21887, a command injection vulnerability, are under mass exploitation and, in some cases, the attackers are delivering crypto-miners.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/01/19/exploited-cve-2023-35082/