HomeSecurityIvanti warns of a new MobileIron zero-day bug

Ivanti warns of new MobileIron zero-day bug

Ivanti warns of a new actively exploited vulnerability (zero-day bug) in MobileIron.

See also: Google search results: Amazon ad leads to fraud

Ivanti warns of new MobileIron zero-day bug

See also: Tesla data breach: Two former employees held responsible

US-based IT software company Ivanti today warned its customers that there is a critical identity response vulnerability in its Sentry application programming interface (API), which is currently being exploited in the real world.

Ivanti Sentry (formerly MobileIron Sentry) acts as a gatekeeper for corporate ActiveSync servers such as Microsoft Exchange Server or backend resources such as SharePoint servers in MobileIron deployments and can also act as a Kerberos Key Distribution Center Proxy (KKDCP) server.

The vulnerability (CVE-2023-38035), discovered and reported by researchers at cybersecurity firm mnemonic, allows unauthenticated attackers to access sensitive gateway configuration APIs exposed on port 8443, used by the MobileIron Configuration Service (MICS).

This is possible after bypassing authentication checks by exploiting an insufficiently restrictive Apache HTTPD configuration.

Successful exploitation allows them to change configuration, execute system commands, or write files on systems running Ivanti Sentry versions 9.18 and earlier.

Ivanti recommends that administrators not expose MICS to the internet and restrict access to internal management networks.

“Currently, we are only aware of a limited number of customers affected by CVE-2023-38035. This vulnerability does not impact other Ivanti products or solutions, such as Ivanti EPMM, MobileIron Cloud, or Ivanti Neurons for MDM,” Ivanti said.

See also: BlackCat ransomware gang hacked Seiko

“As soon as we learned of the vulnerability, we immediately mobilized resources to fix the issue and have RPM scripts available now for all supported versions. We recommend that customers first upgrade to a supported version and then apply the RPM script designed specifically for their version,” the company added.

Ivanti provides detailed information about applying Sentry security updates to systems running supported versions in this article.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS