
Ivanti is warning users to update their Endpoint Manager Mobile (EPMM) mobile device management software (formerly MobileIron Core) to the latest version that fixes an actively exploited zero-day vulnerability.
dubbing CVE-2023-35078, this issue has been described as a remote, unauthenticated API access vulnerability affecting currently supported versions 11.4 releases 11.10, 11.9, and 11.8 and older releases. The maximum severity rating on the CVSS scale is 10.
In a brief advisory, the company said, “An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality and resources of applications without proper authentication.”
“Exploiting this vulnerability could allow an unauthorized, remote (Internet-facing) attacker to access a user’s private information and make limited changes to the server.”
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) said attackers with access to API paths could abuse them to obtain personally identifiable information (PII) such as user names, phone numbers and other mobile device details on vulnerable systems.
Shielding Against Insider Threats: Mastering SaaS Security Posture Management
Worried about insider threats? We’ve got you covered! Join us for this webinar to explore practical strategies and proactive security secrets using SaaS Security Posture Management.
join today
“An attacker could also make other configuration changes, such as creating EPMM-managed accounts that can make further changes to vulnerable systems,” added CISA.
The Utah-based IT software company also said it was aware of the bug being actively exploited against a “very limited number of customers,” but did not provide further details about the nature of the attack or the identity of the attacker behind it.
According to security researcher Kevin Beaumont, patches for this issue are available for versions 11.8.1.1, 11.9.1.1, and 11.10.0.2.