Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
Summary
| CVE | CVE-2023-35078 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-25 07:15:00 UTC |
| Updated | 2023-08-04 18:30:00 UTC |
| Description | Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core, through 11.10 allows remote attackers to obtain PII, add an administrative account, and change the configuration because of an authentication bypass, as exploited in the wild in July 2023. A patch is available. |
Risk And Classification
EPSS: 0.944380000 probability, percentile 0.999880000 (date 2026-04-21)
CISA KEV: Listed on 2023-07-25; due 2023-08-15; ransomware use Known
Problem Types: CWE-287
CISA Known Exploited Vulnerability
| Vendor | Ivanti |
|---|---|
| Product | Endpoint Manager Mobile (EPMM) |
| Name | Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability |
| Required Action | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
| Notes | https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2023-35078 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ivanti | Endpoint Manager Mobile | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ivanti Releases Security Updates for Endpoint Manager Mobile (EPMM) CVE-2023-35078 | CISA | MISC | www.cisa.gov | |
| Ivanti Community | MISC | forums.ivanti.com | |
| CVE-2023-35078 - New Ivanti EPMM Vulnerability | MISC | www.ivanti.com | |
| forums.ivanti.com/s/article/KB-Remote-unauthenticated-API-access-vulnerability-... | MISC | forums.ivanti.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.