CVE-2023-35082
CRITICAL KEV CISA Exploitation: ACTIVE
Ransomware noto
10.0
CVSS 3.0
Description
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
CISA Known Exploited Vulnerability
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA description
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Ivanti | EPMM | — | 11.10 ≤ 11.10 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | adp | CWE-noinfo Not enough information |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.0 | cna | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |