
Security researchers at DEVCORE have disclosed details about several vulnerabilities affecting MobileIron's mobile device management (MDM) solutions. One of these vulnerabilities could be exploited by an unauthorized user to remotely execute code on vulnerable servers.
Researchers discovered the vulnerabilities and reported them to MobileIron in early April. Patches were released on June 15, and a guide.
The vulnerabilities can be used by hackers for remote code execution (CVE-2020-15505), to read files from a targeted system (CVE-2020-15507), and to bypass authentication mechanisms (CVE-2020-15506).
Which MobileIron products are affected?
Products affected include MobileIron Core (version 10.6 and earlier), MobileIron Sentry, MobileIron Cloud, Enterprise Connector , and Reporting Database.
The company (DEVCORE) said it decided to analyze products because of their widespread use. According to the researchers' estimates, at least 20,000 enterprises use its products and more than 15% of the Global Fortune 500 companies had MobileIron servers exposed to the Internet. Among these companies is Facebook.

Last year, one of DEVCORE's researchers, Orange Tsai, disclosed several other critical vulnerabilities affecting enterprise VPN products from Palo Alto Networks, Fortinet, and Pulse Secure. Those vulnerabilities were exploited by various hackers, including state-run hacking groups.
Orange Tsai told SecurityWeek that exploiting the CVE-2020-15505 vulnerability could allow remote code execution on a vulnerable MobileIron server.
According to the researchers, there are about 10,000 potentially exposed servers on the Internet. The worrying thing is that while the patch has been in place for months, 30% of the servers have not received the update and therefore remain vulnerable.
Facebook had not updated its server even two weeks after the patch was released, so researchers reported the issue through its bug bounty program.
Shortly after Orange Tsai disclosed the vulnerability, someone created and released a proof-of-concept (PoC) exploit for CVE-2020-15505.
