EXPOSURES › CVE-2020-15505
CVE-2020-15505
HIGH ⌖ ON CISA KEV · EXPLOITEDIvanti MobileIron products suffered a remote code execution vulnerability that was actively exploited in the wild.
Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database products contained an unspecified vulnerability allowing remote code execution. This failure is critical for DIB organizations because MobileIron is a common endpoint management tool, and an RCE flaw enables attackers to fully compromise devices, steal data, and pivot laterally. Organizations must ensure all MobileIron components are patched immediately and monitor for signs of compromise.
Shame score — The vulnerability was actively exploited in the wild (KEV list) and linked to ransomware campaigns, indicating a severe, avoidable failure in patch management and security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.
"Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution."
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |