CVE-2023-35081

unknown KEV
Published 2023-07-31 · Modified 2023-07-31
CVSS v3
CVSS v2
VIR risk
1.5

Description

Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable).

CISA KEV

Vendor
Ivanti
Product
Endpoint Manager Mobile (EPMM)
Due date
2023-08-21

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2023-35081

Exploits

References

Verify integrity in audit chain (admin only). AS-IS.