Executive brief
Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that allows an authenticated administrator to perform arbitrary file writes to the appliance. This flaw can be chained with CVE-2023-35078 to bypass authentication and ACL restrictions, potentially leading to remote code execution.
Affected products
- Ivanti Endpoint Manager Mobile (EPMM) 11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2, 11.8.x < 11.8.1.2
Timeline
- 2023-07-31: disclosed
- 2023-07-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-08-03: advisory: NVD Published Date
- 2023-07-31: exploited: Reported as exploited in the wild in the advisory summary.