Junglewise Threat Intelligence

CVE-2023-35081: Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability

CVE-2023-35081 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2023-07-31

Technologies: Ivanti Endpoint Manager Mobile (EPMM), Ivanti MobileIron Core. Vendors: Ivanti.

Executive brief

Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that allows an authenticated administrator to perform arbitrary file writes to the appliance. This flaw can be chained with CVE-2023-35078 to bypass authentication and ACL restrictions, potentially leading to remote code execution.

Affected products

  • Ivanti Endpoint Manager Mobile (EPMM) 11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2, 11.8.x < 11.8.1.2

Timeline

  • 2023-07-31: disclosed
  • 2023-07-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-08-03: advisory: NVD Published Date
  • 2023-07-31: exploited: Reported as exploited in the wild in the advisory summary.

Related threats