Back to overview

CVE-2023-35082

CRITICAL KEV CISA Exploitation: ACTIVE Ransomware noto
10.0
CVSS 3.0
Description
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

Metadata

CVE ID
CVE-2023-35082
State
PUBLISHED
Assigner
hackerone
Reserved
2023-06-13 01:00 UTC
Published
2023-08-15 15:11 UTC
Last updated
2025-10-21 23:05 UTC
Vendor / Product
Ivanti / EPMM
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
Vendor
Ivanti
Product
Endpoint Manager Mobile (EPMM) and MobileIron Core
Added to KEV
2024-01-18
Due date
2024-02-08
Ransomware
Known use
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA description
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.
Affected products (1)
VendorProductPlatformVersions
Ivanti EPMM 11.10 ≤ 11.10
Weakness (CWE)
CWESourceDescription
adp CWE-noinfo Not enough information
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview