Auth Bypass in Ivanti EPMM: Unauthorized Access
CVE-2023-35078 Published on July 25, 2023

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

NVD

Known Exploited Vulnerability

This Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes, including creating an EPMM administrative account that can make further c.

The following remediation steps are recommended / required by August 15, 2023: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness Type

What is an authentification Vulnerability?

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

CVE-2023-35078 has been classified to as an authentification vulnerability or weakness.


Products Associated with CVE-2023-35078

Want to know whenever a new CVE is published for Ivanti Endpoint Manager Mobile? stack.watch will email you.

 

Affected Versions

Ivanti Endpoint Manager Mobile: ivanti endpoint_manager_mobile: ivanti endpoint_manager_mobile: ivanti endpoint_manager_mobile: ivanti endpoint_manager_mobile:

Exploit Probability

EPSS
94.47%
Percentile
100.00%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.