Security
Loading…

CVE-2023-35078

CRITICALCVSS 9.8Known Exploited
Description

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.

Timeline
Published:July 25th, 2023 7:15 AM
Last modified:August 5th, 2026 5:16 AM
Added to KEV:July 25th, 2023
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

ivanti

Products

endpoint_manager_mobile
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute