First published: Tue Nov 14 2023(Updated: )
A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized access and potential misuse of user accounts and resources.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Endpoint Manager Mobile | <11.9.0 | |
Ivanti Endpoint Manager Mobile | >=11.10.0<11.10.0.4 | |
Ivanti Endpoint Manager Mobile | >=11.11.0<11.11.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39335 is a security vulnerability in EPMM Versions 11.10, 11.9, and 11.8 and older that allows an unauthenticated threat actor to impersonate any existing user during the device enrollment process.
CVE-2023-39335 poses a significant security risk as it enables unauthorized access and potential malicious activities.
The severity of CVE-2023-39335 is classified as critical with a severity value of 9.8.
EPMM Versions 11.10, 11.9, and 11.8 and older are affected by CVE-2023-39335.
To fix CVE-2023-39335, it is recommended to upgrade the affected EPMM software versions to a secure version provided by Ivanti.