Ivanti discloses new critical auth bypass bug in MobileIron Core

Share:

IT software company Ivanti disclosed today a new critical security vulnerability in its MobileIron Core mobile device management software.

Tracked as CVE-2023-35082, the flaw is a remote unauthenticated API access vulnerability affecting MobileIron Core version 11.2 and older.

Successful exploitation allows attackers to access personally identifiable information (PII) of mobile device users and backdoor compromised servers by deploying web shells when chaining the bug with other flaws.

Ivanti said it would not issue security patches to fix this flaw because it has already been addressed in newer versions of the product, rebranded to Endpoint Manager Mobile (EPMM).

“MobileIron Core 11.2 has been out of support since March 15, 2022. Therefore, Ivanti will not be issuing a patch or any other remediations to address this vulnerability in 11.2 or earlier versions. Upgrading to the latest version of Ivanti Endpoint Manager Mobile (EPMM) is the best way to protect your environment from threats,” the company said.

“This vulnerability does not affect any version of Ivanti Endpoint Manager or MobileIron Core 11.3 and above, or Ivanti Neurons for MDM. Our Support team is always available to help customers to upgrade,” Ivanti said in a separate security advisory.

According to Shodan, more than 2,200 MobileIron user portals are currently exposed online, including over a dozen connected to U.S. local and state government agencies.

Rapid7 security researcher Stephen Fewer, who discovered and reported the bug, provides indicators of compromise (IOCs) to help defenders detect signs of a CVE-2023-35082 attack and urges Ivanti customers to update MobileIron Core software to the latest version immediately.​

Caitlin Condon CVE-2023-35078 tweet

Similar Ivanti bugs exploited in attacks since April

Two other security flaws in Ivanti’s Endpoint Manager Mobile (EPMM) (formerly MobileIron Core) have been exploited by state hackers since April, according to a CISA advisory published on Tuesday.

One of the flaws (CVE-2023-35078), a critical authentication bypass, was exploited as a zero-day to breach the networks of multiple Norwegian government entities.

This vulnerability can be chained with a directory traversal flaw (CVE-2023-35081), allowing threat actors with administrative privileges to deploy web shells on compromised systems.

“Advanced persistent threat (APT) actors exploited CVE-2023-35078 as a zero day from at least April 2023 through July 2023 to gather information from several Norwegian organizations, as well as to gain access to and compromise a Norwegian government agency’s network,” CISA said.

“Mobile device management (MDM) systems are attractive targets for threat actors because they provide elevated access to thousands of mobile devices, and APT actors have exploited a previous MobileIron vulnerability. Consequently, CISA and NCSC-NO are concerned about the potential for widespread exploitation in government and private sector networks.”

CISA’s joint advisory with Norway’s National Cyber Security Centre (NCSC-NO) followed orders asking U.S. federal agencies to patch the two actively exploited flaws by August 15 and August 21.

 

(c) Lawrence Abrams

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
8:44 am, May 19, 2025
weather icon 12°C
L: 11° | H: 13°
overcast clouds
Humidity: 78 %
Pressure: 1021 mb
Wind: 7 mph NNE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:02 am
Sunset: 8:51 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
11° | 13°°C 0 mm 0% 11 mph 77 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
10° | 21°°C 0 mm 0% 9 mph 69 % 1022 mb 0 mm/h
Wed May 21 10:00 pm
weather icon
14° | 22°°C 0 mm 0% 12 mph 63 % 1020 mb 0 mm/h
Thu May 22 10:00 pm
weather icon
11° | 18°°C 0 mm 0% 12 mph 64 % 1023 mb 0 mm/h
Fri May 23 10:00 pm
weather icon
7° | 19°°C 0 mm 0% 9 mph 69 % 1024 mb 0 mm/h
Today 10:00 am
weather icon
12° | 14°°C 0 mm 0% 7 mph 77 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
14° | 18°°C 0 mm 0% 9 mph 67 % 1021 mb 0 mm/h
Today 4:00 pm
weather icon
16° | 19°°C 0 mm 0% 11 mph 52 % 1020 mb 0 mm/h
Today 7:00 pm
weather icon
17° | 17°°C 0 mm 0% 9 mph 46 % 1020 mb 0 mm/h
Today 10:00 pm
weather icon
13° | 13°°C 0 mm 0% 6 mph 63 % 1021 mb 0 mm/h
Tomorrow 1:00 am
weather icon
11° | 11°°C 0 mm 0% 5 mph 66 % 1022 mb 0 mm/h
Tomorrow 4:00 am
weather icon
10° | 10°°C 0 mm 0% 5 mph 69 % 1021 mb 0 mm/h
Tomorrow 7:00 am
weather icon
11° | 11°°C 0 mm 0% 6 mph 63 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,831.07
-0.79%
Ethereum(ETH)
€2,142.07
-4.25%
Tether(USDT)
€0.89
0.00%
XRP(XRP)
€2.07
-2.99%
Solana(SOL)
€144.24
-4.92%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.194922
-0.98%
Shiba Inu(SHIB)
€0.000013
-2.92%
Pepe(PEPE)
€0.000012
0.43%
Peanut the Squirrel(PNUT)
€0.285736
-7.51%
Scroll to Top