CVE-2023-35078 is a critical authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core. This flaw allows unauthenticated attackers to access restricted functionality, potentially leading to full compromise of enrolled devices. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating extremely high exploitability, it presents a severe risk due to its network-based attack vector and low complexity. The vulnerability is actively exploited in the wild, including in known ransomware campaigns, and has garnered significant community attention and media coverage, despite a lack of public Metasploit or ExploitDB modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.8.1.1CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* | ||
>= 11.9.0, < 11.9.1.1CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* | ||
>= 11.10, < 11.10.0.2CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.