ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Norway says a zero-day vulnerability in Ivanti's EPMM software led to cyber attacks on 12 ministries

The Norwegian National Security Authority said recent cyber attacks suffered by twelve government ministries were a result of hackers exploiting a zero-day vulnerability in Ivanti’s Endpoint Manager Mobile software.Utah-based Ivanti is a well-known IT software provider, selling a number of advanced enterprise solutions such as Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core, which enables organisations to securely access and manage their business data on any endpoint used by their employees, contractors, and frontline workers.On July 24, Norwegian authorities reported that twelve government ministries fell victim to a cyber attack. The Norwegian Security and Service Organization (DSS) said that the cyber attack did not affect the Prime Minister’s Office, the Ministry of Defense, the Ministry of Justice, and the Ministry of Foreign Affairs.In a separate update, the DSS said that threat actors exploited a zero-day vulnerability in Ivanti’s Endpoint Manager Mobile software that resulted in security incidents at the ministries. Ivanti soon issued a security patch that closed the vulnerability in DSS’s systems.“This vulnerability was unique, and was discovered for the very first time here in Norway. If we had released the information about the vulnerability too early, it could have contributed to it being misused elsewhere in Norway and in the rest of the world. The update is now generally available and it is prudent to announce what kind of vulnerability it is,” said Sofie Nystrøm, director of the National Security Agency.Norway’s Nation Cyber Security Centre has notified all known organisations in Norway that use the MobileIron Core software to apply the security update as soon as they receive it from the provider.“A zero-day vulnerability presents an opportunity for a threat actor to exploit a vulnerability that the manufacturer and users are not aware of. This type of vulnerability is difficult to protect against,” NCSC said.“Since the discovery of the vulnerability, NSM has worked to notify other Norwegian businesses that use the same software. In addition, there has been an ongoing dialogue with the software manufacturer and other national and international partners.”Acknowledging the reports of the zero-day vulnerability identified in its software, Ivanti said that the vulnerability, assigned CVE-2023-35078, is a “Remote Unauthenticated API Access Vulnerability which can be exploited by threat actors to potentially access users’ personally identifiable information and make limited changes to the server.”“We have received information from a credible source indicating exploitation has occurred. We continue to work with our customers and partners to investigate this situation. We are only aware of a very limited number of customers that have been impacted,” Ivanti said.The US Cybersecurity and Infrastructure Security Agency (CISA) has also released an alert explaining that the vulnerability can be exploited by threat actors with access to specific API paths to obtain sensitive data including name, phone number, and other mobile device details.“An attacker can also make other configuration changes, including creating an EPMM administrative account that can make further changes to a vulnerable system,” CISA said.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543