Ivanti discloses new critical auth bypass bug in MobileIron Core

Teilen:

IT software company Ivanti disclosed today a new critical security vulnerability in its MobileIron Core mobile device management software.

Tracked as CVE-2023-35082, the flaw is a remote unauthenticated API access vulnerability affecting MobileIron Core version 11.2 and older.

Successful exploitation allows attackers to access personally identifiable information (PII) of mobile device users and backdoor compromised servers by deploying web shells when chaining the bug with other flaws.

Ivanti said it would not issue security patches to fix this flaw because it has already been addressed in newer versions of the product, rebranded to Endpoint Manager Mobile (EPMM).

“MobileIron Core 11.2 has been out of support since March 15, 2022. Therefore, Ivanti will not be issuing a patch or any other remediations to address this vulnerability in 11.2 or earlier versions. Upgrading to the latest version of Ivanti Endpoint Manager Mobile (EPMM) is the best way to protect your environment from threats,” the company sagte.

“This vulnerability does not affect any version of Ivanti Endpoint Manager or MobileIron Core 11.3 and above, or Ivanti Neurons for MDM. Our Support team is always available to help customers to upgrade,” Ivanti sagte in a separate security advisory.

According to Shodan, more than 2,200 MobileIron user portals are currently exposed online, including over a dozen connected to U.S. local and state government agencies.

Rapid7 security researcher Stephen Fewer, who discovered and reported the bug, provides indicators of compromise (IOCs) to help defenders detect signs of a CVE-2023-35082 attack and urges Ivanti customers to update MobileIron Core software to the latest version immediately.​

Caitlin Condon CVE-2023-35078 tweet

Similar Ivanti bugs exploited in attacks since April

Two other security flaws in Ivanti’s Endpoint Manager Mobile (EPMM) (formerly MobileIron Core) have been exploited by state hackers since April, according to a CISA advisory published on Tuesday.

One of the flaws (CVE-2023-35078), a critical authentication bypass, was exploited as a zero-day to breach the networks of multiple Norwegian government entities.

This vulnerability can be chained with a directory traversal flaw (CVE-2023-35081), allowing threat actors with administrative privileges to deploy web shells on compromised systems.

“Advanced persistent threat (APT) actors exploited CVE-2023-35078 as a zero day from at least April 2023 through July 2023 to gather information from several Norwegian organizations, as well as to gain access to and compromise a Norwegian government agency’s network,” CISA sagte.

“Mobile device management (MDM) systems are attractive targets for threat actors because they provide elevated access to thousands of mobile devices, and APT actors have exploited a previous MobileIron vulnerability. Consequently, CISA and NCSC-NO are concerned about the potential for widespread exploitation in government and private sector networks.”

CISA’s joint advisory with Norway’s National Cyber Security Centre (NCSC-NO) followed orders asking U.S. federal agencies to patch the two actively exploited flaws by August 15 und August 21.

 

(c) Lawrence Abrams

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:31 am, Mai 24, 2025
Wetter-Symbol 13°C
L: 13° | H: 14°
light rain
Luftfeuchtigkeit: 90 %
Druck: 1012 mb
Wind: 7 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0.42 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:56 am
Sonnenuntergang: 8:58 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
13° | 14°°C 0.43 mm 43% 13 mph 92 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 20°°C 0.93 mm 93% 16 mph 90 % 1015 mb 0 mm/h
Mo. Mai 26 10:00 pm
Wetter-Symbol
10° | 17°°C 1 mm 100% 13 mph 79 % 1018 mb 0 mm/h
Di. Mai 27 10:00 pm
Wetter-Symbol
13° | 20°°C 1 mm 100% 14 mph 91 % 1017 mb 0 mm/h
Mi. Mai 28 10:00 pm
Wetter-Symbol
14° | 21°°C 1 mm 100% 16 mph 97 % 1018 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
14° | 16°°C 0.24 mm 24% 10 mph 92 % 1012 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 22°°C 0 mm 0% 13 mph 70 % 1012 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 13 mph 54 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
19° | 19°°C 0.43 mm 43% 9 mph 77 % 1011 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 11 mph 88 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 12 mph 85 % 1009 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 15°°C 0.93 mm 93% 15 mph 90 % 1007 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
14° | 14°°C 0.25 mm 25% 16 mph 75 % 1007 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€95,178.46
-2.15%
Ethereum(ETH)
€2,243.65
-4.64%
Fesseln(USDT)
€0.88
0.02%
XRP(XRP)
€2.06
-4.20%
Solana(SOL)
€153.86
-3.27%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.200753
-7.09%
Shiba Inu(SHIB)
€0.000012
-6.65%
Pepe(PEPE)
€0.000012
-9.92%
Peanut das Eichhörnchen(PNUT)
€0.308353
-5.92%
Nach oben scrollen