CRITICAL

CVE-2023-35082

Ivanti Endpoint Manager Mobile 2023-08-15 CVSS v3.1
CVSS
9.8
KEV

Description

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

Summary dbcve.org

Authentication bypass vulnerability in Ivanti EPMM 11.10 and older allowing unauthorized access to restricted application functionality without proper authentication. The flaw enables attackers to circumvent authentication mechanisms and access sensitive resources or administrative functions.

Mitigation

Apply vendor-supplied patch/update to Ivanti EPMM to a version newer than 11.10 to remediate the authentication bypass. If immediate patching is not possible, restrict network access to the EPMM management interface via firewall or VPN.

Weakness (CWE)

CWE-287 Improper Authentication

EPSS Score

100%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE