Skip to content

CVE-2023-35078 | Endpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core, through 11.10 allows remote attackers to obtain PII, add an administrative account, and change the configuration because of an authentication bypass, as exploited in the wild in July 2023. A patch is available..This CVE has a CVSS3.1 score of 10 and a Base Severity of CRITICAL.

InfoDetails
CVE IDCVE-2023-35078
CVE StatePUBLISHED
BaseScore10
BaseSeverityCRITICAL
VectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
VersionNA

References for CVE-2023-35078 :
https://www.ivanti.com/blog/cve-2023-35078-new-ivanti-epmm-vulnerability
https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability
https://www.cisa.gov/news-events/alerts/2023/07/24/ivanti-releases-security-updates-endpoint-manager-mobile-epmm-cve-2023-35078
https://forums.ivanti.com/s/article/KB-Remote-unauthenticated-API-access-vulnerability-CVE-2023-35078

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)LOW
PrivilegesRequired(PR)NONE
UserInteraction(UI)NONE
Scope(S)CHANGED
Confidentiality(C)HIGH
Availability(A)HIGH
Integrity(I)HIGH