New high-severity Ivanti bug reported, second in a week
Summary
It was revealed last week the earlier bug (tracked as CVE-2023-35078 and with a maximum-possible CVSS v3 rating of 10) was exploited in an attack against a dozen ministries within the Norwegian government. The newly identified bug (tracked as CVE-2023-35081) is a path traversal vulnerability with a CVSS v3 rating of 7.2 that allows an attacker to write arbitrary files onto the appliance. In an advisory published on Friday, Ivanti said the new vulnerability impacted all versions of EPMM (previously known as MobileIron Core) and it was “critical” that users took immediate action to remediate their instances. That was confirmed in the Ivanti advisory, which stated: “Successful exploitation can be used to write malicious files to the appliance, ultimately allowing a malicious actor to execute OS commands on the appliance as the tomcat user.” Apache Tomcat is a popular open-source Java application server which was identified last week as being the target for attackers spreading Marai botnet malware. Last week CISA added CVE-2023-35078 to its Known Exploited Vulnerabilities catalog and ordered all Federal Civilian Executive Branch government agencies to remediate the flow by August 15.