Junglewise Threat Intelligence

CVE-2023-35082: Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

CVE-2023-35082 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-01-18

Technologies: Ivanti Endpoint Manager Mobile (EPMM), Ivanti MobileIron Core. Vendors: Ivanti.

Executive brief

An authentication bypass vulnerability in Ivanti EPMM and MobileIron Core allows unauthenticated remote attackers to access restricted functionality or resources. This flaw specifically impacts the API and is distinct from CVE-2023-35078.

Affected products

  • Ivanti Endpoint Manager Mobile (EPMM) 11.10 and older
  • Ivanti MobileIron Core 11.2 and older

Timeline

  • 2023-08-15: disclosed: NVD Published Date
  • 2024-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-01-18: advisory: Advisory published/updated with KEV status

Related threats