New high-severity Ivanti bug reported, second in a week

General News

Summary

It was revealed last week the earlier bug (tracked as CVE-2023-35078 and with a maximum-possible CVSS v3 rating of 10) was exploited in an attack against a dozen ministries within the Norwegian government. The newly identified bug (tracked as CVE-2023-35081) is a path traversal vulnerability with a CVSS v3 rating of 7.2 that allows an attacker to write arbitrary files onto the appliance. In an advisory published on Friday, Ivanti said the new vulnerability impacted all versions of EPMM (previously known as MobileIron Core) and it was “critical” that users took immediate action to remediate their instances. That was confirmed in the Ivanti advisory, which stated: “Successful exploitation can be used to write malicious files to the appliance, ultimately allowing a malicious actor to execute OS commands on the appliance as the tomcat user.” Apache Tomcat is a popular open-source Java application server which was identified last week as being the target for attackers spreading Marai botnet malware. Last week CISA added CVE-2023-35078 to its Known Exploited Vulnerabilities catalog and ordered all Federal Civilian Executive Branch government agencies to remediate the flow by August 15.

Classifications

industries
Aerospace
applications
Web and Content Management

AskAI Classifications

Labels
Enterprise Software Unified Endpoint Management Security Software

Linked Companies

Ivanti
$500M to $1B