Security vendor Ivanti has released an update to its Avalanche mobile device management product which fixes 22 vulnerabilities, 13 of which are rated critical.
Ivanti Avalanche is described by the vendor as an enterprise MDM solution capable of managing distributed deployments of more than 100,000 mobile devices - including anything from warehouse scanners to handheld tablets.
Its Avalanche 6.4.2 release published this week includes fixes for 13 flaws rated with a CVSS score of 9.8.
They are a mix of stack-based buffer overflow remote code execution vulnerabilities, heap-based buffer overflow RCE and unauthenticated buffer overflows.
There's no suggestion the vulnerabilities are currently being exploited in active attacks, but Ivanti MDM products have in the past been targeted by threat actors.
Over the summer, the vendor was forced to patch multiple zero-day vulnerabilities in its Ivanti Endpoint Manager Mobile, formerly known as MobileIron Core.
CVE-2023-35078 and CVE-2023-35081 were exploited in a likely state-sponsored attacks against several Norwegian government ministries.
Alongside the 13 critical-rated vulnerabilities, Ivanti fixed a further nine high and medium severity bugs with its Avalanche 6.4.2 release.
This Cyber News was published on www.infosecurity-magazine.com. Publication date: Thu, 21 Dec 2023 10:30:19 +0000