Skip to content
COOEY

EXPOSURES › CVE-2020-15505

CVE-2020-15505

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-15505 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildransomwareunpatched

Ivanti MobileIron products suffered a remote code execution vulnerability that was actively exploited in the wild.

Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database products contained an unspecified vulnerability allowing remote code execution. This failure is critical for DIB organizations because MobileIron is a common endpoint management tool, and an RCE flaw enables attackers to fully compromise devices, steal data, and pivot laterally. Organizations must ensure all MobileIron components are patched immediately and monitor for signs of compromise.

Shame score — The vulnerability was actively exploited in the wild (KEV list) and linked to ransomware campaigns, indicating a severe, avoidable failure in patch management and security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Critical vulnerability in core products poses significant risk to enterprise security posture.
cooey ↗ severe-fallout -0.80
Critical vulnerability in core products poses significant risk to enterprise security posture.
"Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized