Security News > 2023 > July > Ivanti patches MobileIron zero-day bug exploited in attacks
Ivanti released security patches for the remote unauthenticated API access vulnerability tracked as CVE-2023-35078 on Sunday.
While Ivanti has published a security advisory to provide details on the security vulnerability, the information is being blocked by a login, given that the article can only be accessed with an account linked to Ivanti customer information.
"The article remains active behind log-in credentials for our customers," an Ivanti spokesperson told BleepingComputer when we asked for more details on the security flaw and for confirmation that it's already being abused in attacks.
While the company has not publicly admitted that the zero-day was actively exploited, the private bulletin says that a "Trusted source" informed Ivanti that CVE-2023-35078 was exploited in attacks against a limited number of customers.
Ivanti added that the bug is not being exploited as part of a supply chain attack, saying that it didn't find "Any indication that this vulnerability was introduced into our code development process maliciously."
"Ivanti became aware and addressed a vulnerability that impacts Ivanti Endpoint Manager Mobile customers," an Ivanti spokesperson BleepingComputer, after a second inquiry asking to confirm exploitation in attacks and if the company will release a public advisory.
News URL
Related news
- Ivanti warns of three more CSA zero-days exploited in attacks (source)
- Rackspace monitoring data stolen in ScienceLogic zero-day attack (source)
- Critical Ivanti RCE flaw with public exploit now used in attacks (source)
- Qualcomm patches high-severity zero-day exploited in attacks (source)
- Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited (source)
- Ivanti fixes three CSA zero-days exploited in the wild (CVE-2024-9379, CVE-2024-9380, CVE-2024-9381) (source)
- Mozilla fixes Firefox zero-day actively exploited in attacks (source)
- Firefox Zero-Day Under Attack: Update Your Browser Immediately (source)
- CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active Zero-Day Attack (source)
- Fortinet warns of new critical FortiManager flaw used in zero-day attacks (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-07-25 | CVE-2023-35078 | Improper Authentication vulnerability in Ivanti Endpoint Manager Mobile An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication. | 9.8 |