HomeSecurityVulnerabilities expose thousands of MobileIron servers to attacks

Vulnerabilities expose thousands of MobileIron servers to attacks

 MobileIron

Security researchers at DEVCORE have disclosed details about several vulnerabilities affecting MobileIron's mobile device management (MDM) solutions. One of these vulnerabilities could be exploited by an unauthorized user to remotely execute code on vulnerable servers.

Researchers discovered the vulnerabilities and reported them to MobileIron in early April. Patches were released on June 15, and a guide.

The vulnerabilities can be used by hackers for remote code execution (CVE-2020-15505), to read files from a targeted system (CVE-2020-15507), and to bypass authentication mechanisms (CVE-2020-15506).

Which MobileIron products are affected?

Products affected include MobileIron Core (version 10.6 and earlier), MobileIron Sentry, MobileIron Cloud, Enterprise Connector , and Reporting Database.

The company (DEVCORE) said it decided to analyze products because of their widespread use. According to the researchers' estimates, at least 20,000 enterprises use its products and more than 15% of the Global Fortune 500 companies had MobileIron servers exposed to the Internet. Among these companies is Facebook.

vulnerabilities

Last year, one of DEVCORE's researchers, Orange Tsai, disclosed several other critical vulnerabilities affecting enterprise VPN products from Palo Alto Networks, Fortinet, and Pulse Secure. Those vulnerabilities were exploited by various hackers, including state-run hacking groups.

Orange Tsai told SecurityWeek that exploiting the CVE-2020-15505 vulnerability could allow remote code execution on a vulnerable MobileIron server.

According to the researchers, there are about 10,000 potentially exposed servers on the Internet. The worrying thing is that while the patch has been in place for months, 30% of the servers have not received the update and therefore remain vulnerable.

Facebook had not updated its server even two weeks after the patch was released, so researchers reported the issue through its bug bounty program.

Shortly after Orange Tsai disclosed the vulnerability, someone created and released a proof-of-concept (PoC) exploit for CVE-2020-15505.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS