CVE-2023-35082 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2024-02-08.
Description
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 100% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | yes — remediate by 2024-02-08 |
| Public exploit | none known |
| Published | 2023-08-15 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability |
|---|---|
| Added | 2024-01-18 |
| Due | 2024-02-08 |
| Vendor / product | Ivanti / Endpoint Manager Mobile (EPMM) and MobileIron Core |
| Ransomware use | known |
Affected (1)
| Vendor | Product |
|---|---|
| ivanti | endpoint manager mobile |
References
- https://forums.ivanti.com/s/article/CVE-2023-35082-Remote-Unauthenticated-API-Access-Vulnerability-in-MobileIron-Core-11-2-and-older?language=en_US
- https://forums.ivanti.com/s/article/CVE-2023-35082-Remote-Unauthenticated-API-Access-Vulnerability-in-MobileIron-Core-11-2-and-older?language=en_US
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-35082
→ the Explorer · watch your stack · NVD