• News/
  • https://www.bleepingcomputer.com/news/security/cisa-critical-ivanti-auth-bypass-bug-now-actively-exploited/

CISA: Critical Ivanti auth bypass bug now actively exploited

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 18, 2024
·
Updated

CISA warns that a critical authentication bypass vulnerability in Ivanti's Endpoint Manager Mobile (EPMM) and MobileIron Core device management software (patched in August 2023) is now under active exploitation. Tracked as CVE-2023-35082, the flaw is a remote unauthenticated API access vulnerability affecting all versions of EPMM 11.10, 11.9, and 11.8 and MobileIron Core 11.7 and below,. Successful exploitation provides attackers access to personally identifiable information (PII) of mobile device users and can let them backdoor compromised servers when chaining the bug with other flaws. "Ivanti has an RPM script available now. We recommend customers first upgrade to a supported version and then apply the RPM script," the company said in August. "More detailed information can be found in this Knowledge Base articleon the Ivanti Community portal." Cybersecurity company Rapid7, which discovered and reported the vulnerability, provides indicators of compromise(IOCs) to help admins detect signs of a CVE-2023-35082 attack. According to Shodan, 6,300 Ivanti EPMM user portals are currently exposed online, while the Shadowserver threat monitoring platform tracks 3,420 Internet-exposed EPMM appliances. Shodan's data also reveals that the more than 150 instances linked to government agencies worldwide can be directly accessed via the Internet. ​While it has yet to provide further details on CVE-2023-35082 active exploitation, CISA added the vulnerability to its Known Exploited Vulnera...

Read full article

Affected Software

4 affected components
Ivanti Endpoint Manager Mobile=11.10
Ivanti Endpoint Manager Mobile=11.9
Ivanti Endpoint Manager Mobile=11.8
MobileIron Core=11.7 and below
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical authentication bypass vulnerability in Ivanti's Endpoint Manager Mobile and MobileIron Core software that is being actively exploited.

2

What security implications are discussed in this article?

The article highlights the risk of unauthorized access to sensitive data due to the authentication bypass vulnerability being exploited.

3

What products or software are affected by this vulnerability?

The affected products include Ivanti Endpoint Manager Mobile versions 11.8, 11.9, and 11.10, as well as MobileIron Core version 11.7 and below.

4

What tracking identifier is associated with this vulnerability?

This vulnerability is tracked as CVE-2023-35082.

5

When was this vulnerability patched?

The vulnerability was patched in August 2023.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203