Alert: Multiple actors are attempting to exploit MobileIron vulnerability CVE 2020-15505
MobileIron remote code execution vulnerability is a target for APT nation state groups and cyber criminals to compromise the networks of UK organisations.

Introduction
In June 2020 MobileIron, a provider of mobile device management (MDM) systems, released security updates to address several vulnerabilities in their products. This included CVE-2020-15505, a remote code execution vulnerability, rated critical.
MDM systems allow system administrators to manage an organisation’s mobile devices from a central server, making them a valuable target for threat actors.
The NCSC is aware that Advanced Persistent Threat (APT) nation-state groups and cyber criminals are now actively attempting to exploit this vulnerability [T1190] to compromise the networks of UK organisations.
The Cybersecurity and Infrastructure Agency (CISA) in the US has also noted that APTs are exploiting this vulnerability in combination with the Netlogon/Zerologon vulnerability CVE-2020-1472 in a single intrusion.1
1. Further information about this example of vulnerability chaining can be found on the CISA website at https://us-cert.cisa.gov/ncas/alerts/aa20-283a. The NCSC has also published an alert on the Netlogon vulnerability at https://ncsc.gov.uk/news/alert-organisations-should-patch-netlogon-vulnerability
What happened
This critical vulnerability affects MobileIron Core and Connector products and could allow a remote attacker to execute arbitrary code on a system. The MobileIron website lists the following versions as affected:
- 10.3.0.3 and earlier
- 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0
- Sentry versions 9.7.2 and earlier
- 9.8.0
- Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier
A proof of concept exploit became available in September 2020 and since then both hostile state actors and cybercriminals have attempted to exploit this vulnerability in the UK. These actors typically scan victim networks to identify vulnerabilities, including CVE-2020-15505, to be used during targeting (T1505.002). In some cases, when the latest updates are not installed, they have successfully compromised systems. The healthcare, local government, logistics and legal sectors have all been targeted but others could also be affected.
More information about the MobileIron vulnerability is available.
Installing security updates
MobileIron made available security updates for all impacted versions on 15 June 2020. Organisations can find all relevant links to the updates on the MobileIron website at https://help.mobileiron.com/s/article-detail-page?Id=kA12T000000g065SAA.2
It is also important for organisations using affected versions to ensure they are following other best-practice cyber security advice, such as scanning their own networks and undertaking continual audits. This will help identify suspicious activity in the event that this vulnerability has already been exploited.
2 Note that to access the updates, a MobileIron account is required to log in.
Conclusion
The NCSC strongly advises that organisations refer to the MobileIron guidance referenced in this alert and ensure the necessary updates are installed in affected versions. Organisations should also keep informed of any future updates to the guidance from MobileIron.
The NCSC generally recommends following vendor best practice advice in the mitigation of vulnerabilities. In the case of this MobileIron vulnerability, the most important aspect is to install the latest updates as soon as practicable.
Additionally the NCSC advices organisations to follow the NCSC guidance in the mitigation section at the end of this alert. UK organisations should report any compromises to the NCSC via our website.
Mitigation
A variety of mitigations will be useful in defending against the campaigns detailed in this report:
- Protect your devices and networks by keeping them up to date: use the latest supported versions, apply security updates promptly, use anti-virus and scan regularly to guard against known malware threats. See NCSC Guidance: https://ncsc.gov.uk/collection/mobile-device-guidance/antivirus-and-other-security-software and https://ncsc.gov.uk/collection/mobile-device-guidance/keeping-devices-and-software-up-to-date
- Prevent and detect lateral movement in your organisation’s networks. See NCSC Guidance: https://ncsc.gov.uk/guidance/preventing-lateral-movement
- Set up a security monitoring capability so you are collecting the data that will be needed to analyse network intrusions. See NCSC Guidance: https://ncsc.gov.uk/guidance/introduction-logging-security-purposes and https://ncsc.gov.uk/information/logging-made-easy
- Restrict intruders' ability to move freely around your systems and networks. Pay particular attention to potentially vulnerable entry points eg third-party systems with onward access to your core network. During an incident, disable remote access from third-party systems until you are sure they are clean. See NCSC Guidance: https://ncsc.gov.uk/guidance/preventing-lateral-movement and https://ncsc.gov.uk/guidance/assessing-supply-chain-security.
- Deploy a host-based intrusion detection system. A variety of products are available, free and paid-for, to suit different needs and budgets.
- Further information: Invest in preventing malware-based attacks across various scenarios. See NCSC Guidance https://www.ncsc.gov.uk/collection/supply-chain-security/assessing-supply-chain-security


