peter bassill · operator
$ cve CVE-2023-35082 JSON

CVE-2023-35082 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2024-02-08.

Description

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-287
On CISA KEVyes — remediate by 2024-02-08
Public exploitnone known
Published2023-08-15
Last modified2026-06-17

CISA KEV

NameIvanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
Added2024-01-18
Due2024-02-08
Vendor / productIvanti / Endpoint Manager Mobile (EPMM) and MobileIron Core
Ransomware useknown

Affected (1)

VendorProduct
ivantiendpoint manager mobile

References

→ the Explorer  ·  watch your stack  ·  NVD