Executive brief
An authentication bypass vulnerability in Ivanti EPMM and MobileIron Core allows unauthenticated remote attackers to access restricted functionality or resources. This flaw specifically impacts the API and is distinct from CVE-2023-35078.
Affected products
- Ivanti Endpoint Manager Mobile (EPMM) 11.10 and older
- Ivanti MobileIron Core 11.2 and older
Timeline
- 2023-08-15: disclosed: NVD Published Date
- 2024-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-01-18: advisory: Advisory published/updated with KEV status