CVE-2023-35082: Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

Published Aug 15, 2023
·
Updated

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

Other sources

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.

CISA

Affected Software

7 affected components
Ivanti Endpoint Manager Mobile<=11.10.0
Ivanti Endpoint Manager Mobile<11.11.0
Ivanti Endpoint Manager Mobile=11.10
Ivanti Endpoint Manager Mobile=11.9
Ivanti Endpoint Manager Mobile=11.8
MobileIron Core=11.7 and below
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    If vendor mitigations are unavailable, discontinue use of the affected product(s): Ivanti Endpoint Manager Mobile (EPMM) versions 11.10 and older; Ivanti MobileIron; MobileIron Core.

Event History

Aug 15, 2023
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
DescriptionSeverity
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 18, 2024
Known Exploited
via CISA·12:00 AM
Known Ransomware
via CISA·12:00 AM
News Published
via BleepingComputer·08:51 PM
News Published
via BleepingComputer·08:53 PM
Jul 13, 2024
News Published
via BleepingComputer·03:16 PM
May 10, 58443
Event
11:24 AM

Peer vulnerabilities

Found alongside the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-35082?

CVE-2023-35082 is an authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allowing unauthorized users to access restricted functionality or resources without proper authentication.

2

How severe is CVE-2023-35082?

CVE-2023-35082 has a severity score of 9.8, indicating it is critical.

3

Which software is affected by CVE-2023-35082?

Ivanti Endpoint Manager Mobile version 11.10.0 and older is affected by CVE-2023-35082.

4

How can unauthorized users exploit CVE-2023-35082?

Unauthorized users can exploit CVE-2023-35082 by bypassing authentication and gaining access to restricted functionality or resources.

5

Is there a fix available for CVE-2023-35082?

Ivanti EPMM users should upgrade to a version newer than 11.10.0 to mitigate the authentication bypass vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203