CVE-2023-35081: Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable).
Other sources
A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Endpoint Manager Mobile (EPMM)to a version that resolves this vulnerability.Fixed in 11.10.0.3 - Upgrade
Upgrade
Ivanti Endpoint Manager Mobile (EPMM)to a version that resolves this vulnerability.Fixed in 11.9.1.2 - Upgrade
Upgrade
Ivanti Endpoint Manager Mobile (EPMM)to a version that resolves this vulnerability.Fixed in 11.8.1.2
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-35081.
What is the severity of CVE-2023-35081?
The severity of CVE-2023-35081 is high with a CVSS score of 7.2.
What is the affected software for CVE-2023-35081?
The affected software for CVE-2023-35081 is Ivanti Endpoint Manager Mobile (EPMM) versions 11.8.0 to 11.10.0.3.
What is the vulnerability description of CVE-2023-35081?
CVE-2023-35081 is a path traversal vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows an authenticated administrator to perform malicious file writes to the EPMM server.
Is there any additional reference for CVE-2023-35081?
Yes, you can find more information about CVE-2023-35081 at the following link: [Ivanti Forum](https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US)