Back to overview

CVE-2023-35078

CRITICAL KEV CISA Exploitation: ACTIVE Ransomware noto
10.0
CVSS 3.0
Description
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

Metadata

CVE ID
CVE-2023-35078
State
PUBLISHED
Assigner
hackerone
Reserved
2023-06-13 01:00 UTC
Published
2023-07-25 06:08 UTC
Last updated
2025-10-21 23:05 UTC
Primary CWE
CWE-287
CWE-287 Improper Authentication
Vendor / Product
Ivanti / Endpoint Manager Mobile
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
Vendor
Ivanti
Product
Endpoint Manager Mobile (EPMM)
Added to KEV
2023-07-25
Due date
2023-08-15
Ransomware
Known use
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA description
Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.
Affected products (1)
VendorProductPlatformVersions
Ivanti Endpoint Manager Mobile 11.10 ≤ 11.10, 11.9 ≤ 11.9, 11.8 ≤ 11.8
Weakness (CWE)
CWESourceDescription
CWE-287 adp CWE-287 Improper Authentication
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview