CISA warns that a critical authentication bypass vulnerability in Ivanti's Endpoint Manager Mobile (EPMM) and MobileIron Core device management software (patched in August 2023) is now under active exploitation. Tracked as CVE-2023-35082, the flaw is a remote unauthenticated API access vulnerability affecting all versions of EPMM 11.10, 11.9, and 11.8 and MobileIron Core 11.7 and below,. Successful exploitation provides attackers access to personally identifiable information (PII) of mobile device users and can let them backdoor compromised servers when chaining the bug with other flaws. "Ivanti has an RPM script available now. We recommend customers first upgrade to a supported version and then apply the RPM script," the company said in August. "More detailed information can be found in this Knowledge Base articleon the Ivanti Community portal." Cybersecurity company Rapid7, which discovered and reported the vulnerability, provides indicators of compromise(IOCs) to help admins detect signs of a CVE-2023-35082 attack. According to Shodan, 6,300 Ivanti EPMM user portals are currently exposed online, while the Shadowserver threat monitoring platform tracks 3,420 Internet-exposed EPMM appliances. Shodan's data also reveals that the more than 150 instances linked to government agencies worldwide can be directly accessed via the Internet. While it has yet to provide further details on CVE-2023-35082 active exploitation, CISA added the vulnerability to its Known Exploited Vulnera...
CISA: Critical Ivanti auth bypass bug now actively exploited
BleepingComputer
·Sergiu Gatlan
·Published Jan 18, 2024
·Updated
Affected Software
4 affected components
Ivanti Endpoint Manager Mobile=11.10
Ivanti Endpoint Manager Mobile=11.9
Ivanti Endpoint Manager Mobile=11.8
MobileIron Core=11.7 and below
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical authentication bypass vulnerability in Ivanti's Endpoint Manager Mobile and MobileIron Core software that is being actively exploited.
2
What security implications are discussed in this article?
The article highlights the risk of unauthorized access to sensitive data due to the authentication bypass vulnerability being exploited.
3
What products or software are affected by this vulnerability?
The affected products include Ivanti Endpoint Manager Mobile versions 11.8, 11.9, and 11.10, as well as MobileIron Core version 11.7 and below.
4
What tracking identifier is associated with this vulnerability?
This vulnerability is tracked as CVE-2023-35082.
5
When was this vulnerability patched?
The vulnerability was patched in August 2023.