Vulnerability record · CVE-2020-15505 · published 7 July 2020
CVE-2020-15505: MobileIron Core, Connector, Sentry and RDB remote code execution
Mobileiron · Core
MobileIron Core, Enterprise Connector, Sentry and Monitor and Reporting Database contain a remote code execution flaw reachable over the network without authentication. The description does not specify the vulnerable code path, but a public reference identifies it as Hessian-based Java deserialization, and the affected product list spans MDM server and connector components. Because these systems manage and communicate with managed mobile devices, compromise of the server is high value for an attacker.
Description
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier that allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated network RCE, KEV listing and near-certain EPSS exploitation probability make this an urgent patch target.
What it is
MobileIron Core, Enterprise Connector, Sentry and Monitor and Reporting Database contain a remote code execution flaw reachable over the network without authentication. The description does not specify the vulnerable code path, but a public reference identifies it as Hessian-based Java deserialization, and the affected product list spans MDM server and connector components. Because these systems manage and communicate with managed mobile devices, compromise of the server is high value for an attacker.
Impact
An unauthenticated remote attacker can execute arbitrary code on the affected MobileIron server or connector, gaining control of the MDM infrastructure and any credentials, device enrollment data or managed-device trust it holds.
Attack surface
The flaw is network reachable (CVSS vector AV:N/AC:L/PR:N/UI:N), so no authentication or user interaction is required. The exact exposed endpoint is not stated in the record, but the public exploit reference points to Hessian-based Java deserialization on the MDM server.
Exploitation
CVE-2020-15505 is listed in CISA KEV with a 2021-11-03 addition date, and EPSS gives a 30-day probability of 0.99737 (99.95th percentile), indicating active exploitation is expected. Public exploit code is referenced by Packet Storm and Perch Security, and KEV notes no known ransomware campaign use.
What to do
- Apply the vendor updates referenced in the MobileIron security advisory for Core, Connector, Sentry and RDB; upgrade off the listed affected versions (10.3.0.3 and earlier, 10.4.0.0 through 10.4.0.3, 10.5.1.0, 10.5.2.0, 10.6.0.0; Sentry 9.7.2 and earlier and 9.8.0; RDB 2.0.0.1 and earlier).
- Restrict network access to MobileIron management and connector interfaces so they are not reachable from untrusted networks or the public internet.
- Place the MDM server and connector behind segmentation and monitor for unexpected outbound connections from those hosts.
- Rotate credentials and certificates stored or used by the affected MobileIron components after patching, in case of prior compromise.
- Review the KEV required action and confirm remediation status against the 2022-05-03 due date.
Detection
- Hunt for Hessian or Java deserialization payloads and unusual serialized-object traffic to MobileIron Core, Connector, Sentry or RDB endpoints.
- Monitor for unexpected child processes, web shells or new files spawned by the MobileIron Java service.
- Alert on anomalous outbound network connections from MobileIron hosts to unfamiliar external addresses.
- Review MobileIron and web server logs for requests to management or connector endpoints from untrusted source IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-15505 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-15505 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-15505), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.