ivanti endpoint-manager-mobile CVE-2023-35078 is a vulnerability in Ivanti Endpoint Manager Mobile
Published on July 25, 2023

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

Vendor Advisory Vendor Advisory Vendor Advisory NVD

Known Exploited Vulnerability

This Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes, including creating an EPMM administrative account that can make further c.

The following remediation steps are recommended / required by August 15, 2023: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Vulnerability Analysis

CVE-2023-35078 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. It has the highest possible exploitability rating (3.9). The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.

What is an authentification Vulnerability?

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

CVE-2023-35078 has been classified to as an authentification vulnerability or weakness.


Products Associated with CVE-2023-35078

You can be notified by stack.watch whenever vulnerabilities like CVE-2023-35078 are published in these products:

 

What versions of Endpoint Manager Mobile are vulnerable to CVE-2023-35078?