• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
ivanti releases urgent patch for epmm zero day vulnerability under active

Ivanti Releases Urgent Patch for EPMM Zero-Day Vulnerability Under Active Exploitation

You are here: Home / General Cyber Security News / Ivanti Releases Urgent Patch for EPMM Zero-Day Vulnerability Under Active Exploitation
July 25, 2023

Ivanti is warning people to update their Endpoint Supervisor Mobile (EPMM) cell system management application (previously MobileIron Main) to the most recent version that fixes an actively exploited zero-working day vulnerability.

Dubbed CVE-2023-35078, the issue has been described as a distant unauthenticated API entry vulnerability that impacts presently supported version 11.4 releases 11.10, 11.9, and 11.8 as nicely as older releases. It has the utmost severity score of 10 on the CVSS scale.

“An authentication bypass vulnerability in Ivanti EPMM enables unauthorized buyers to entry restricted functionality or methods of the software without the need of proper authentication,” the enterprise said in a terse advisory.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“If exploited, this vulnerability permits an unauthorized, remote (internet-facing) actor to likely accessibility users’ individually identifiable information and facts and make minimal alterations to the server.”

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) said an adversary with entry to the API paths could exploit them to receive personally identifiable details (PII) this kind of as names, phone quantities, and other cell product facts for users on a vulnerable technique.

Upcoming WEBINARShield Versus Insider Threats: Grasp SaaS Security Posture Administration

Concerned about insider threats? We have acquired you coated! Sign up for this webinar to explore useful methods and the insider secrets of proactive security with SaaS Security Posture Management.

Sign up for These days

“An attacker can also make other configuration changes, together with producing an EPMM administrative account that can make even more variations to a susceptible technique,” CISA extra.

The Utah-based IT application company further more said that it truly is mindful of lively exploitation of the bug towards a “very constrained number of clients” but did not disclose added details about the mother nature of the attacks or the identity of the risk actor behind them.

Patches for the issue have been produced offered in versions 11.8.1.1, 11.9.1.1, and 11.10..2, in accordance to security researcher Kevin Beaumont.

Observed this post appealing? Comply with us on Twitter  and LinkedIn to study far more special material we article.


Some elements of this short article are sourced from:
thehackernews.com

Previous Post: «apple rolls out urgent patches for zero day flaws impacting iphones, Apple Rolls Out Urgent Patches for Zero-Day Flaws Impacting iPhones, iPads and Macs
Next Post: Atlassian Releases Patches for Critical Flaws in Confluence and Bamboo atlassian releases patches for critical flaws in confluence and bamboo»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New FjordPhantom Android Malware Targets Banking Apps in Southeast Asia
  • Qakbot Takedown Aftermath: Mitigations and Protecting Against Future Threats
  • Chinese Hackers Using SugarGh0st RAT to Target South Korea and Uzbekistan
  • Discover How Gcore Thwarted Powerful 1.1Tbps and 1.6Tbps DDoS Attacks
  • WhatsApp’s New Secret Code Feature Lets Users Protect Private Chats with Password
  • U.S. Treasury Sanctions North Korean Kimsuky Hackers and 8 Foreign Agents
  • Zyxel Releases Patches to Fix 15 Flaws in NAS, Firewall, and AP Devices
  • Zero-Day Alert: Apple Rolls Out iOS, macOS, and Safari Patches for 2 Actively Exploited Flaws
  • Google Unveils RETVec – Gmail’s New Defense Against Spam and Malicious Emails
  • North Korea’s Lazarus Group Rakes in $3 Billion from Cryptocurrency Hacks

Copyright © TheCyberSecurity.News, All Rights Reserved.