CVE-2023-39335: Critical severity ivanti endpoint manager mobile (epmm) vulnerability
A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized access and potential misuse of user accounts and resources.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39335?
CVE-2023-39335 is a security vulnerability in EPMM Versions 11.10, 11.9, and 11.8 and older that allows an unauthenticated threat actor to impersonate any existing user during the device enrollment process.
How does CVE-2023-39335 impact security?
CVE-2023-39335 poses a significant security risk as it enables unauthorized access and potential malicious activities.
What is the severity of CVE-2023-39335?
The severity of CVE-2023-39335 is classified as critical with a severity value of 9.8.
Which software versions are affected by CVE-2023-39335?
EPMM Versions 11.10, 11.9, and 11.8 and older are affected by CVE-2023-39335.
How can I fix CVE-2023-39335?
To fix CVE-2023-39335, it is recommended to upgrade the affected EPMM software versions to a secure version provided by Ivanti.