HomeSecurityCISA: Warns government agencies to fix Ivanti flaw

CISA: Warns government agencies to fix Ivanti flaw

The Center for Cybersecurity and Infrastructure Security (CISA) has issued a warning to U.S. federal agencies, urging them to protect systems from a serious authentication bypass vulnerability in Ivanti's Endpoint Manager Mobile (EPMM), formerly MobileIron Core.

See also: CISA: Federal agencies must immediately update Adobe ColdFusion servers
CISA

Dubbed CVE-2023-35078, this vulnerability was exploited as a zero-day to compromise a software platform used by 12 Norwegian ministries, according to the country's National Security Authority.

The uncontrolled exploit allows unauthorized attackers to gain remote access to specific API paths, without authentication, with the aim of stealing personally identifiable information (PII), such as names, phone numbers, and other device details.

Additionally, it is possible to make changes to the configuration of compromised devices, including the creation of EPMM administrative accounts. These accounts provide the necessary privileges to make further changes to vulnerable systems.

Ivanti has also confirmed that the vulnerability is being actively exploited in attacks and has warned customers that it is important to take immediate action to ensure their systems are fully protected.

While the company has not yet released indicators of compromise (IOCs), security experts and researchers say they include information about the vulnerability required to exploit the vulnerability. This allows threat actors to quickly create their own exploits and further enhance attacks.

See also: CISA: Warns federal agencies about recent Barracuda zero-day bug
Ivanti

According to Shodan, there are nearly 2,900 MobileIron user portals accessible online. Of these, about 36 belong to local and state government agencies in the US.

Given the current situation, it is essential that administrators immediately upgrade their Ivanti EPMM (MobileIron) installations to the latest version in order to protect their systems from potential attacks.

The US Federal Civilian Executive Branch (FCEB) has three weeks, until August 15, to protect devices from attacks targeting the CVE-2023-35078 vulnerability, which was added to CISA's list of known exploitable vulnerabilities on Tuesday.

Under the Mandatory Business Directive (BOD 22-01), issued in November 2021, federal agencies must now scan their networks for vulnerable devices and address any security deficiencies added to CISA's KEV list.

See also: CISA: Asks federal agencies to immediately update iPhones and Macs

While the list primarily concerns US federal agencies, it is highly recommended that private companies prioritize and implement patches for all vulnerabilities listed on CISA's list of bugs that are exploited in attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS