Published 08/31/2023
Norwegian authorities recently revealed a critical zero-day vulnerability in Ivanti Endpoint Manager Mobile (EPMM), posing a significant security threat. The flaw allows unauthenticated remote attackers to bypass authentication and access the server’s API, potentially leading to data theft and unauthorized system modifications.
On July 24th, the Norwegian Government Security and Service Organization (DSS) and the Norwegian National Security Agency (NSM) informed the public about a zero-day vulnerability in Ivanti Endpoint Manager Mobile (EPMM), a mobile management software that can be used for mobile device management and mobile application/content management (Tenable). This vulnerability has a maximum CVSS score of 10, indicating it is very easy to exploit and requires no specialized tools or skills (Mnemonic).
This vulnerability, classified as CVE-2023-35078, is an authentication bypass in Ivanti’s EPMM. An unauthenticated remote attacker could exploit this vulnerability to access the server’s application programming interface (API), which is normally accessible only to authenticated users (Tenable). Successful exploitation would allow an attacker to be able to access “specific API paths”. By using these unrestricted API paths, a malicious actor could steal personally identifiable information (PII), such as names, phone numbers, and other mobile device details. An attacker can also make other configuration changes, including creating an EPMM administrative account on the server that can further modify a vulnerable system (CISA). The attack consists of changing the URI path to the API v2, which can, in fact, be accessed without any authentication methods (Mnemonic). According to the API documentation, all API calls use the URL format https://[core-server]/api/v2/. If we add the path to a vulnerable endpoint, it is easy to execute commands without needing authentication, as shown here: https://[core-server]/vulnerable/path/api/v2. Luckily, it is fairly simple to detect whether the vulnerability has been exploited in a system. This can be done by checking the logs from the mobile management software to determine if the API v2 endpoint in Ivanti’s EPMM has been targeted (Uzun). This may be evident if regular API calls to unusual paths are present in the logs.
Ivanti reported that the vulnerability impacts all supported versions – Version 11.4 releases 11.10, 11.9 and 11.8. Older unsupported versions/releases are also at risk (CISA). Furthermore, the company has promptly issued security patches for the EPMM vulnerability. Customers can fix it by upgrading the software to EPMM versions 11.8.1.1, 11.9.1.1, and 11.10.0.2. These fixed versions also cover unsupported and End-of-Life (EoL) software versions that are lower than 11.8.1.0 (Uzun).
According to the articles posted by Ivanti, the vulnerability was exploited in the wild as a zero-day against a small number of customers (Tenable). However, it is known that the unnamed attackers utilized this flaw to compromise 12 government ministries in Norway (Muncaster).
Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
Establish and Maintain a Remediation Process: Establish and maintain a risk-based remediation strategy documented in a remediation process, with monthly or more frequent reviews.
Perform Automated Application Patch Management: Apply updates to enterprise assets through automated patch management on a monthly or more frequent basis.
Perform Automated Vulnerability Scans of Internal Enterprise Assets: Perform automated vulnerability scans of internal enterprise assets on a quarterly or more frequent basis. Conduct both authenticated and unauthenticated scans, using a SCAP-compliant vulnerability scanning tool.
Remediate Detected Vulnerabilities: Remediate detected vulnerabilities in software through processes and tooling on a monthly or more frequent basis, based on the remediation process.
Ensure Network Infrastructure is Up-to-Date: Keep network infrastructure up-to-date. Example implementations include running the latest stable software release and/or using currently supported network-as-a-service (NaaS) offerings. Review software versions monthly or more frequently to verify support.
Establish and Maintain a Penetration Testing Program: Establish and maintain a penetration testing program appropriate to the enterprise's size, complexity, and maturity. Penetration testing program characteristics include scope, such as network, web application, Application Programming Interface (API), hosted services, and physical premise controls; frequency; limitations, such as acceptable hours, and excluded attack types; point of contact information; remediation, such as how findings will be routed internally; and retrospective requirements.
Manage Default Accounts on Enterprise Assets and Software: Perform periodic external penetration tests, at least annually, in accordance with program requirements. External penetration testing must include enterprise and environmental reconnaissance to detect exploitable information. Penetration testing requires specialized skills and experience and must be conducted through a qualified party. The testing may be a clear box or an opaque box.
Remediate Penetration Test Findings: Remediate penetration test findings based on the enterprise’s policy for remediation scope and prioritization.
Mnemonic. (2023, July 25). Advisory: Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability. https://www.mnemonic.io/resources/blog/ivanti-endpoint-manager-mobileepmm-authentication-bypass-vulnerability/
Tenable®. (2023, July 25). CVE-2023-35078: IVaNti Endpoint Manager Mobile (EPMM) / MobileIron Core Unauthenticated API Access vulnerability. https://www.tenable.com/blog/cve-2023-35078-ivanti-endpoint-managermobile-epmm-mobileiron-core-unauthenticated-api-access
Uzun, T. (2023, July 25). A critical zero-day in Ivanti EPMM (Formerly MobileIron Core) is actively exploited (CVE-2023-35078). SOCRadar® Cyber Intelligence Inc. https://socradar.io/critical-zero-day-in-ivanti-epmm-formerly-mobileiron-core-isactively-exploited-cve-2023-35078/
Cybersecurity and Infrastructure Security Agency CISA. (2023, July 24). Ivanti releases a security update for Endpoint Manager Mobile (EPMM) addressing CVE-2023-35078. https://www.cisa.gov/news-events/alerts/2023/07/24/ivanti-releases-securityupdates-endpoint-manager-mobile-epmm-cve-2023-35078
Muncaster, P. (2023, July 25). Ivanti patches a Zero-Day bug used in attacks in Norway. Infosecurity Magazine. https://www.infosecurity-magazine.com/news/ivantipatches-zeroday-bug-norway/
Uzun, T. (2023, August 4). A critical zero-day in Ivanti EPMM (formerly MobileIron Core) is actively exploited (CVE-2023-35078). SOCRadar® Cyber Intelligence Inc. https://socradar.io/critical-zero-day-in-ivanti-epmm-formerly-mobileiron-core-isactively-exploited-cve-2023-35078/
Contributing Security Analysts: Nahyan Jamil, Erika Delvalle, Alessandro Lovadina, Sreten Dedic, EJ Bulut, Uday Bilakhiy, Yousef Blassy.