HackerFeeds
All CVEs

CVE-2023-35078

CRITICAL9.8
CISA KEV

Published 2023-07-25 · Updated 2026-08-05 · Source support@hackerone.com

Description

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CWE-287CWE-287

CISA Known-Exploited Vulnerability

Product: IvantiEndpoint Manager Mobile (EPMM)

Name: Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

Date added: 2023-07-25 · Due: 2023-08-15

USED IN RANSOMWARE

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

View on NVD