The Center for Cybersecurity and Infrastructure Security (CISA) has issued a warning to U.S. federal agencies, urging them to protect systems from a serious authentication bypass vulnerability in Ivanti's Endpoint Manager Mobile (EPMM), formerly MobileIron Core.
See also: CISA: Federal agencies must immediately update Adobe ColdFusion servers

Dubbed CVE-2023-35078, this vulnerability was exploited as a zero-day to compromise a software platform used by 12 Norwegian ministries, according to the country's National Security Authority.
The uncontrolled exploit allows unauthorized attackers to gain remote access to specific API paths, without authentication, with the aim of stealing personally identifiable information (PII), such as names, phone numbers, and other device details.
Additionally, it is possible to make changes to the configuration of compromised devices, including the creation of EPMM administrative accounts. These accounts provide the necessary privileges to make further changes to vulnerable systems.
Ivanti has also confirmed that the vulnerability is being actively exploited in attacks and has warned customers that it is important to take immediate action to ensure their systems are fully protected.
While the company has not yet released indicators of compromise (IOCs), security experts and researchers say they include information about the vulnerability required to exploit the vulnerability. This allows threat actors to quickly create their own exploits and further enhance attacks.
See also: CISA: Warns federal agencies about recent Barracuda zero-day bug

According to Shodan, there are nearly 2,900 MobileIron user portals accessible online. Of these, about 36 belong to local and state government agencies in the US.
Given the current situation, it is essential that administrators immediately upgrade their Ivanti EPMM (MobileIron) installations to the latest version in order to protect their systems from potential attacks.
The US Federal Civilian Executive Branch (FCEB) has three weeks, until August 15, to protect devices from attacks targeting the CVE-2023-35078 vulnerability, which was added to CISA's list of known exploitable vulnerabilities on Tuesday.
Under the Mandatory Business Directive (BOD 22-01), issued in November 2021, federal agencies must now scan their networks for vulnerable devices and address any security deficiencies added to CISA's KEV list.
See also: CISA: Asks federal agencies to immediately update iPhones and Macs
While the list primarily concerns US federal agencies, it is highly recommended that private companies prioritize and implement patches for all vulnerabilities listed on CISA's list of bugs that are exploited in attacks.
