HomeSecurityCISA: New warning about actively exploited Ivanti MobileIron bugs

CISA: New warning about actively exploited Ivanti MobileIron bugs

CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) today warned of government hackers exploiting two flaws in Ivanti's Endpoint Manager Mobile (EPMM), formerly MobileIron Core, since April.

See also: CISA: Warns government agencies to fix Ivanti flaw

“Advanced Persistent Attackers (APTs) exploited CVE-2023-35078 as a zero day from at least April 2023 to July 2023 to collect information from various Norwegian organizations, as well as to gain access to and compromise the network of a Norwegian government agency,” CISA said on Tuesday

“Mobile device management (MDM) systems are attractive targets for attackers because they provide increased access to thousands of mobile devices, and APT attackers have exploited a previous MobileIron vulnerability.

“As a result, CISA and NCSC-NO are concerned about the potential for widespread exploitation across government and private sector networks.”.

One of the flaws (CVE-2023-35078), a critical authentication bypass vulnerability that was exploited as a zero-day in attacks targeting Norwegian government entities, can be linked to a second directory traversal flaw (CVE-2023-35081) that allows attackers with administrator privileges to deploy web shells.

CISA: New warning about actively exploited Ivanti MobileIron bugs

The flaw, CVE-2023-35078, allows attackers to create the EPMM administrative accounts needed to chain the two security flaws.

After successful exploitation, attackers can access specific API paths, potentially leading to the theft of personally identifiable information (PII), with the compromised data containing names, phone numbers, and other mobile device details.

The Norwegian Data Protection Authority (DPA) was also notified following the attacks targeting the networks of Norwegian organizations, likely due to concerns that hackers may have accessed and/or stolen sensitive data from the compromised government systems.

Proposal: CISA: Federal agencies must immediately update Adobe ColdFusion servers

As Shodan reports, there are currently more than 2,300 accessible MobileIron user portals exposed online, including more than a dozen connected to local and state U.S. government agencies.

CISA: New warning about actively exploited Ivanti MobileIron bugs

Today's warning comes as a joint advisory issued in collaboration with the National Cyber ​​Security Center of Norway (NCSC-NO) and follows an order asking US federal agencies to patch one of these two actively exploited flaws by August 15.

CISA also ordered federal agencies on Monday to patch their systems against the CVE-2023-35081 exploit by August 21.

“These types of vulnerabilities are a common means of attack for malicious cyber actors and pose significant risks to federal business,” the US cybersecurity agency warned a week ago.

With this data, security teams and administrators are urged to immediately upgrade Ivanti EPMM (MobileIron) to the latest version to secure their systems from ongoing attacks.

They should also consider MDM as high-value assets (HVA) that require additional restrictions and monitoring, as they can provide increased access to networks of thousands of managed devices.

Read also: CISA: Warns federal agencies about recent Barracuda zero-day bug

source of information:bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS