Junglewise Threat Intelligence

CVE-2020-15505: Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability

CVE-2020-15505 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Ivanti MobileIron Sentry. Vendors: Ivanti.

Executive brief

A remote code execution vulnerability exists in multiple Ivanti MobileIron products, including Core & Connector, Sentry, and the Monitor and Reporting Database. The flaw allows unauthenticated attackers to execute arbitrary code via unspecified vectors, reportedly involving Hessian-based Java deserialization.

Affected products

  • Ivanti MobileIron Core & Connector 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0, 10.6.0.0
  • Ivanti MobileIron Sentry 9.7.2 and earlier, 9.8.0
  • Ivanti MobileIron Monitor and Reporting Database (RDB) 2.0.0.1 and earlier

Timeline

  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed