CVE-2023-35082: Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.
Other sources
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If vendor mitigations are unavailable, discontinue use of the affected product(s): Ivanti Endpoint Manager Mobile (EPMM) versions 11.10 and older; Ivanti MobileIron; MobileIron Core.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-35082?
CVE-2023-35082 is an authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allowing unauthorized users to access restricted functionality or resources without proper authentication.
How severe is CVE-2023-35082?
CVE-2023-35082 has a severity score of 9.8, indicating it is critical.
Which software is affected by CVE-2023-35082?
Ivanti Endpoint Manager Mobile version 11.10.0 and older is affected by CVE-2023-35082.
How can unauthorized users exploit CVE-2023-35082?
Unauthorized users can exploit CVE-2023-35082 by bypassing authentication and gaining access to restricted functionality or resources.
Is there a fix available for CVE-2023-35082?
Ivanti EPMM users should upgrade to a version newer than 11.10.0 to mitigate the authentication bypass vulnerability.