The UK's National Cyber Security Centre (NCSC) issued an alert yesterday, urging all organisations to patch the critical remote code execution vulnerability CVE-2020-15505 (RCE) in the MobileIron mobile device management (MDM) platform.

MDM is a software platform that allows admins to manage remote mobile devices in their organization, including pushing apps, updates, and the ability to change settings. This management is done from a central location, such as an admin console running on the organization's server, making it a prime target for attackers.
The NCSC warns that they are aware of hacking groups actively using the MobileIron vulnerability CVE-2020-1550 to compromise various networks in the healthcare, local government, logistics, and legal sectors.
“The NCSC is aware that some Advanced Persistent Threat (APT) groups and cybercriminals are attempting to exploit this vulnerability to compromise the networks of UK organisations,” the advisory states.
The US Governmental Security and Infrastructure Security Agency (CISA) has also warned that APT hacking groups are actively using this vulnerability to gain access to various networks. The US (NSA) states that CVE-2020-15505 is in the Top-25 vulnerabilities used by Chinese state hackers.
The MobileIron vulnerability CVE-2020-15505 allows an attacker to remotely execute commands on an MDM server without requiring authentication.
MDM servers must be publicly accessible to manage remote mobile devices - this makes them a very good target for threat actors.
The vulnerability was discovered and responsibly disclosed by security researcher Orange Tsai in March, and MobileIron released patches and an advisory in June.
Shortly thereafter, researchers released a proof-of-concept (PoC) exploit for the vulnerability that allows remote attackers to execute commands on vulnerable devices.
After that, some APT or government groups started using the vulnerability in various compromised networks.
The UK NCSC strongly urges all organisations using vulnerable software to apply patches immediately.
The MobileIron versions that are vulnerable to CVE-2020-15505 are the following:
- 10.3.0.3 and earlier
- 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0
- Sentry versions 9.7.2 and earlier
- 9.8.0
- Database Monitoring and Reporting (RDB) version 2.0.0.1 (and earlier versions)
Information about available patches can be found in the MobileIron advisory
