Ivanti discloses new critical auth bypass bug in MobileIron Core

Share:

IT software company Ivanti disclosed today a new critical security vulnerability in its MobileIron Core mobile device management software.

Tracked as CVE-2023-35082, the flaw is a remote unauthenticated API access vulnerability affecting MobileIron Core version 11.2 and older.

Successful exploitation allows attackers to access personally identifiable information (PII) of mobile device users and backdoor compromised servers by deploying web shells when chaining the bug with other flaws.

Ivanti said it would not issue security patches to fix this flaw because it has already been addressed in newer versions of the product, rebranded to Endpoint Manager Mobile (EPMM).

“MobileIron Core 11.2 has been out of support since March 15, 2022. Therefore, Ivanti will not be issuing a patch or any other remediations to address this vulnerability in 11.2 or earlier versions. Upgrading to the latest version of Ivanti Endpoint Manager Mobile (EPMM) is the best way to protect your environment from threats,” the company said.

“This vulnerability does not affect any version of Ivanti Endpoint Manager or MobileIron Core 11.3 and above, or Ivanti Neurons for MDM. Our Support team is always available to help customers to upgrade,” Ivanti said in a separate security advisory.

According to Shodan, more than 2,200 MobileIron user portals are currently exposed online, including over a dozen connected to U.S. local and state government agencies.

Rapid7 security researcher Stephen Fewer, who discovered and reported the bug, provides indicators of compromise (IOCs) to help defenders detect signs of a CVE-2023-35082 attack and urges Ivanti customers to update MobileIron Core software to the latest version immediately.​

Caitlin Condon CVE-2023-35078 tweet

Similar Ivanti bugs exploited in attacks since April

Two other security flaws in Ivanti’s Endpoint Manager Mobile (EPMM) (formerly MobileIron Core) have been exploited by state hackers since April, according to a CISA advisory published on Tuesday.

One of the flaws (CVE-2023-35078), a critical authentication bypass, was exploited as a zero-day to breach the networks of multiple Norwegian government entities.

This vulnerability can be chained with a directory traversal flaw (CVE-2023-35081), allowing threat actors with administrative privileges to deploy web shells on compromised systems.

“Advanced persistent threat (APT) actors exploited CVE-2023-35078 as a zero day from at least April 2023 through July 2023 to gather information from several Norwegian organizations, as well as to gain access to and compromise a Norwegian government agency’s network,” CISA said.

“Mobile device management (MDM) systems are attractive targets for threat actors because they provide elevated access to thousands of mobile devices, and APT actors have exploited a previous MobileIron vulnerability. Consequently, CISA and NCSC-NO are concerned about the potential for widespread exploitation in government and private sector networks.”

CISA’s joint advisory with Norway’s National Cyber Security Centre (NCSC-NO) followed orders asking U.S. federal agencies to patch the two actively exploited flaws by August 15 and August 21.

 

(c) Lawrence Abrams

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:15 am, Jul 13, 2025
weather icon 21°C
L: 20° | H: 22°
clear sky
Humidity: 64 %
Pressure: 1013 mb
Wind: 4 mph NE
Wind Gust: 5 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 2%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:58 am
Sunset: 9:13 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
20° | 22°°C 0 mm 0% 6 mph 58 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
19° | 27°°C 0 mm 0% 15 mph 71 % 1015 mb 0 mm/h
Tue Jul 15 10:00 pm
weather icon
15° | 22°°C 1 mm 100% 17 mph 85 % 1016 mb 0 mm/h
Wed Jul 16 10:00 pm
weather icon
14° | 27°°C 0.11 mm 11% 11 mph 85 % 1017 mb 0 mm/h
Thu Jul 17 10:00 pm
weather icon
18° | 27°°C 1 mm 100% 13 mph 95 % 1015 mb 0 mm/h
Today 1:00 pm
weather icon
23° | 27°°C 0 mm 0% 3 mph 58 % 1013 mb 0 mm/h
Today 4:00 pm
weather icon
27° | 30°°C 0 mm 0% 0 mph 40 % 1011 mb 0 mm/h
Today 7:00 pm
weather icon
27° | 27°°C 0 mm 0% 6 mph 31 % 1008 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 6 mph 40 % 1010 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 0 mm 0% 5 mph 40 % 1011 mb 0 mm/h
Tomorrow 4:00 am
weather icon
20° | 20°°C 0 mm 0% 5 mph 52 % 1010 mb 0 mm/h
Tomorrow 7:00 am
weather icon
19° | 19°°C 0 mm 0% 9 mph 71 % 1011 mb 0 mm/h
Tomorrow 10:00 am
weather icon
23° | 23°°C 0 mm 0% 12 mph 54 % 1012 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,868.58
-0.02%
Ethereum(ETH)
€2,528.78
-0.30%
XRP(XRP)
€2.40
0.36%
Tether(USDT)
€0.86
0.00%
Solana(SOL)
€138.69
-0.22%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.169590
-1.20%
Shiba Inu(SHIB)
€0.000011
-1.10%
Pepe(PEPE)
€0.000010
-2.43%
Peanut the Squirrel(PNUT)
€0.246209
7.19%
Scroll to Top