CVE-2023-35082KEV · OVERDUE

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

Critical · published August 15, 2023

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 10.0. It is confirmed in active exploitation. It sits in the 100.0th percentile for exploit probability.

941
days past CISA
deadline
CVSS v3.0
10.0
EPSS
100%
Percentile
100.0
In the wild
Confirmed
What it is

🚨 An authentication bypass is lurking in Ivanti EPMM 11.10 and older! This flaw lets unauthorized users access sensitive parts of the application like a VIP crashing a private party. 🔥 Think of it like a concert where someone sneaks in through the backstage door. They can wander around areas meant only for performers, potentially causing chaos without a ticket or permission! This vulnerability could lead to unauthorized access to critical functionalities within the application. Imagine an intruder being able to change settings, access sensitive data, or even manipulate user accounts without anyone knowing—absolutely devastating!

Put simply

Think of it like a concert where someone sneaks in through the backstage door. They can wander around areas meant only for performers, potentially causing chaos without a ticket or permission! CVE-2023-35082 allows attackers to bypass authentication checks in Ivanti EPMM, granting them access to restricted resources without proper credentials.

What to do

This vulnerability could lead to unauthorized access to critical functionalities within the application. Imagine an intruder being able to change settings, access sensitive data, or even manipulate user accounts without anyone knowing—absolutely devastating! Update to Ivanti EPMM version 11.11 or later to patch this vulnerability. Additionally, review user access controls and ensure proper authentication measures are enforced across the board. Don't wait—act now! You’ve got this! Follow these steps, and you’ll be a security hero in no time! 🦸

The record
Technical detail
CVSS v3.0
10.0 · CRITICAL
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.99999 · 100.0th percentile
Published
2023-08-15T15:11Z
KEV added
2024-01-18 · due 2024-02-08
EPSS history
Timeline
  • 18 JAN 00:00Z
    Added to CISA KEV — remediate by Feb 8
    kev
  • 15 AUG 15:11Z
    An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the…
    cvelistv5