CVE-2023-35078

unknown KEV
Published 2023-07-25 · Modified 2023-07-25
CVSS v3
CVSS v2
VIR risk
1.5

Description

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.

CISA KEV

Vendor
Ivanti
Product
Endpoint Manager Mobile (EPMM)
Due date
2023-08-15

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2023-35078

Exploits

References

Verify integrity in audit chain (admin only). AS-IS.