Security News > 2023 > July > Ivanti patches MobileIron zero-day bug exploited in attacks
Ivanti released security patches for the remote unauthenticated API access vulnerability tracked as CVE-2023-35078 on Sunday.
While Ivanti has published a security advisory to provide details on the security vulnerability, the information is being blocked by a login, given that the article can only be accessed with an account linked to Ivanti customer information.
"The article remains active behind log-in credentials for our customers," an Ivanti spokesperson told BleepingComputer when we asked for more details on the security flaw and for confirmation that it's already being abused in attacks.
While the company has not publicly admitted that the zero-day was actively exploited, the private bulletin says that a "Trusted source" informed Ivanti that CVE-2023-35078 was exploited in attacks against a limited number of customers.
Ivanti added that the bug is not being exploited as part of a supply chain attack, saying that it didn't find "Any indication that this vulnerability was introduced into our code development process maliciously."
"Ivanti became aware and addressed a vulnerability that impacts Ivanti Endpoint Manager Mobile customers," an Ivanti spokesperson BleepingComputer, after a second inquiry asking to confirm exploitation in attacks and if the company will release a public advisory.
News URL
Related news
- Ivanti fixes VPN gateway vulnerability allowing RCE, DoS attacks (source)
- Microsoft fixes two Windows zero-days exploited in malware attacks (source)
- Zero-Day Alert: Critical Palo Alto Networks PAN-OS Flaw Under Active Attack (source)
- Palo Alto Networks warns of PAN-OS firewall zero-day used in attacks (source)
- Hackers Deploy Python Backdoor in Palo Alto Zero-Day Attack (source)
- Week in review: Palo Alto Networks firewalls under attack, Microsoft patches two exploited zero-days (source)
- MITRE says state hackers breached its network via Ivanti zero-days (source)
- Critical Update: CrushFTP Zero-Day Flaw Exploited in Targeted Attacks (source)
- MITRE breached by nation-state threat actor via Ivanti zero-days (source)
- Google fixes fifth Chrome zero-day exploited in attacks this year (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-07-25 | CVE-2023-35078 | Improper Authentication vulnerability in Ivanti Endpoint Manager Mobile An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication. | 9.8 |