Cybersecurity Failures in Enterprise MDM Platforms

An Analytical Study of the Ivanti Case

doi: 10.32567/hm.2026.2.4

Absztrakt

Mobile Device Management (MDM) platforms have evolved into critical components of enterprise security architectures, influencing device governance, access control and policy enforcement across corporate networks. As these systems increasingly operate as centralised control planes, they have become attractive targets for adversaries seeking scalable organisational compromise. The study develops a comprehensive analytical framework that integrates public Ivanti security incident data with vulnerability assessment documents and current MDM system design materials. Through qualitative incident analysis and architectural interpretation, the research identifies three primary factors that amplify the systemic impact of MDM compromise: excessive privilege concentration, identity adjacency and update trust dependencies. The findings demonstrate that the security significance of MDM systems extends beyond conventional endpoint management, as these platforms increasingly influence authentication processes, trust relationships and enterprise-wide security decisions. The study argues that MDM platforms should be governed as high-value control-plane assets requiring architectural risk management rather than solely operational security maintenance. The results contribute to the broader understanding of centralised management infrastructures and highlight the need for stronger segmentation, authentication controls, and trust-boundary protection mechanisms within modern enterprise environments.

Kulcsszavak:

Mobile Device Management MDM security Ivanti enterprise security architecture identity management

Hogyan kell idézni

Paráda, I. (2026). Cybersecurity Failures in Enterprise MDM Platforms: An Analytical Study of the Ivanti Case. Hadmérnök, 21(2), 61–74. https://doi.org/10.32567/hm.2026.2.4

Hivatkozások

ALPÁR, Gergely – HOEPMAN, Jaap-Henk – SILJEE, Johanneke (2011): The Identity Crisis: Security, Privacy and Usability Issues in Identity Management. arXiv. Online: https://arxiv.org/abs/1101.0427

ANDERSON, Ross (2020): Security Engineering. A Guide to Building Dependable Distributed Systems. Cambridge: Cambridge University Press. Online: https://doi.org/10.1002/9781119644682

ANDERSON, Elliot (2025): CVE-2024-24996, CVE-2024-29204 Ivanti Avalanche Buffer Overflow Vulnerabilities. Online: https://www.lumificyber.com/threat-library/cve-2024-24996-cve-2024-29204-ivanti-avalanche-buffer-overflow-vulnerabilities/

AZODOLMOLKY, Siamak (2013): Software Defined Networking with OpenFlow. Online: https://speetis.fei.tuke.sk/KomunikacnaTechnika1/prednasky/7_11_2016/kniha_sietovanie.pdf

BÁLINT, Ferenc – PETŐ, Richárd (2025): Sustainable and Safe Cities Through Computer Applications 2025. Interdisciplinary Description of Complex Systems, 23(3), 207–216. Online: https://hrcak.srce.hr/file/481559

CAPPOS, Justin – SAMUEL, Justin – BAKER, Scott M. – HARTMAN, John H. (2008): A Look in the Mirror: Attacks on Package Managers. CCS ’08: Proceedings of the 15th ACM Conference on Computer and Communications Security. New York: Association for Computing Machinery, 565–574. Online: https://doi.org/10.1145/1455770.1455841

CELIK, Osman (2025): Attack Surface Management Report. Online: https://www.wisdominterface.com/wp-content/uploads/2025/07/Report2025KuppingerColeLeadershipCompassAttackSurfaceManagement-1.pdf

Center for Cybersecurity Belgium (2025): Warning: CVE-2025-22462, Authentication Bypass Vulnerability in Ivanti Neurons for ITSM Leading to Remote Unauthenticated Administrative Access, Patch Immediately! Online: https://ccb.belgium.be/advisories/warning-cve-2025-22462-authentication-bypass-vulnerability-ivanti-neurons-itsm-leading

CIPOLLA, Tom – AL DANA, Lina – KUMAR, Sunil (2025): Market Guide for Endpoint Management Tools. Gartner Research. Online: https://www.gartner.com/en/documents/4018596

CISA (2024): Known Exploited Vulnerabilities Catalog. Ivanti. Online: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Computer Incident Response Center Luxembourg (2023): CVE-2023-46806 (GCVE-0-2023-46806). Online: https://cvepremium.circl.lu/vuln/CVE-2023-46806

CVE Details (2026): Ivanti: Vulnerability Statistics. Online: https://www.cvedetails.com/vendor/17398/Ivanti.html

ELYASSA, Mehdi (2024): Red Teaming Like an APT, a MobileIron 0-day Exploit Chain. Online: https://www.sstic.org/media/SSTIC2024/SSTIC-actes/simulation_dun_apt_en_red_team__recherche_et_dcouv/SSTIC2024-Article-simulation_dun_apt_en_red_team__recherche_et_dcouverte_de_0-day_sur_mobileiron-elyassa.pdf

ENISA (2025): ENISA Threat Landscape 2025. European Union Agency for Cybersecurity. Online: https://www.enisa.europa.eu/sites/default/files/2026-01/ENISA%20Threat%20Landscape%202025_v1.2.pdf

ENISA Cyber Threats (2026): Single Points of Failure in Critical ICT Systems. Online: https://www.enisa.europa.eu/topics/cyber-threats

HAYES, Darren – CAPPA, Francesco – LE-KHAC, Nhien An (2020): An Effective Approach to Mobile Device Management. Digital Business, 1(1). Online: https://doi.org/10.1016/j.digbus.2020.100001

HOGAN-BURNEY, Amy – TSYGANSKIY, Igor (2025): Microsoft Digital Defense Report 2025. Online: https://www.microsoft.com/security/blog

HOWELL, Gema – FRANKLIN, Joshua – SRITAPAN, Vincent – SOUPPAYA, Murugiah – SCARFONE, Karen (2023): NIST SP 800-124 Rev.2. Guidelines for Managing the Security of Mobile Devices in the Enterprise. Online: https://doi.org/10.6028/NIST.SP.800-124r2

ISO/IEC (2022): ISO/IEC 27001:2022. Risk-based Security Methodology. Online: https://www.iso.org/standard/27001

KOVACEVIC, Ivana – RANKOVIC, Tamara – STOJKOV, Milan – SIMIC, Milos (2024): Token-Based Identity Management in Distributed Cloud Systems. arXiv. Online: https://arxiv.org/abs/2410.21865

Microsoft (2023): Enterprise Access Model. Microsoft Security Documentation 2023. Online: https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-access-model

MOORE, Justin (2025): Critical Vulnerabilities in Ivanti EPMM Exploited. Online: https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/

NARANG, Satnam (2023): CVE-2023-38035: Ivanti Sentry API Authentication Bypass Zero-Day Exploited in the Wild. Online: https://fr.tenable.com/blog/cve-2023-38035-ivanti-sentry-api-authentication-bypass-zero-day-exploited-in-the-wild

NIST (2024): CVE-2024-22026 Detail. National Vulnerability Database. Online: https://nvd.nist.gov/vuln/detail/CVE-2024-22026

ROSE, Scott – BORCHERT, Oliver – MITCHELL, Stu – CONNELLY, Sean (2020): Zero Trust Architecture. NIST SP 800-207. Online: https://doi.org/10.6028/NIST.SP.800-207

SALTZER, Jerome H. – SCHROEDER, Michael D. (1975): The Protection of Information in Computer Systems. Proceedings of the IEEE, 63(9), 1278–1308. Online: https://doi.org/10.1109/PROC.1975.9939

SINGER, Peter W. – FRIEDMAN, Allan (2014): Cybersecurity and Cyberwar. What Everyone Needs to Know. Oxford: Oxford University Press. Online: https://doi.org/10.1093/wentk/9780199918096.001.0001

SMITH, Ben (2025): CVE-2025-4427, CVE-2025-4428: Ivanti Endpoint Manager Mobile (EPMM) Remote Code Execution. Online: https://www.tenable.com/blog/cve-2025-4427-cve-2025-4428-ivanti-endpoint-manager-mobile-epmm-remote-code-execution

SYYNIMAA, Nestori (2022): Exploring Azure Active Directory Attack Surface: Enumerating Authentication Methods with Open-Source Intelligence Tools. Proceedings of the 24th International Conference on Enterprise Information Systems, Volume 2, ICEIS, 142–147. Online: https://doi.org/10.5220/0011077100003179

TÓTH, András (2025): Enhancing Situational Awareness and Decision-Making: The Impact of Advanced ISR Solutions on Command and Control Systems. Hadmérnök, 20(2), 143–160. Online: https://doi.org/10.32567/hm.2025.2.9

TÓTH, András – FARKAS, Tibor (2023): Opportunities and Directions for the Evolution of Command and Control Systems in the Context of Multi-domain Operations. Vojenské Reflexie, 18(3), 59–73. Online: https://doi.org/10.52651/vr.a.2023.3.59-73

WINDLEY, Phillip (2005): Digital Identity. O’Reilly. Online: https://dl.acm.org/doi/abs/10.5555/1098715

YAMIN, Muhammad – KATT, Basel (2019): Mobile Device Management (MDM): Technologies, Issues, and Challenges. ICCSP ’19: Proceedings of the 3rd International Conference on Cryptography, Security and Privacy. New York: Association for Computing Machinery, 143–147. Online: https://doi.org/10.1145/3309074.3309103