Zero-day vulnerability in Endpoint Manager Mobile (formerly MobileIron Core)

Improper Authentication
CVE-2023-35078

Vulnerability details

Advisory: SB2023072510 - Authentication bypass in Ivanti Endpoint Manager Mobile (formerly MobileIron Core)

Vulnerable component: Endpoint Manager Mobile (formerly MobileIron Core)

CVE-ID: CVE-2023-35078

CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-287 - Improper Authentication

Description:

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an unspecified error in the authentication process. A remote attacker can bypass authentication and gain unauthorized access to the application.

Note, the vulnerability is being actively exploited in the wild as per Ivanti customers. The company at the moment did not comment on the incident and concealed all information about this vulnerability.

External links:

https://www.bleepingcomputer.com/news/security/ivanti-patches-mobileiron-zero-day-bug-exploited-in-attacks/