Junglewise Threat Intelligence

CVE-2023-35078: Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

CVE-2023-35078 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-07-25

Technologies: Ivanti Endpoint Manager Mobile (EPMM), Ivanti MobileIron Core. Vendors: Ivanti.

Executive brief

An authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM) allows unauthenticated remote attackers to access restricted API paths. Successful exploitation enables access to personally identifiable information (PII) and allows unauthorized configuration changes, such as modifying security profiles or installing software on registered devices.

Affected products

  • Ivanti Endpoint Manager Mobile (EPMM) up to 11.10.0.2

Timeline

  • 2023-07-24: advisory: CISA and Ivanti release initial alerts and security updates.
  • 2023-07-25: disclosed
  • 2023-07-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2023-07-25: exploited: Exploitation in the wild reported as occurring in July 2023.

Related threats