CVE-2023-35082

CVE Published 2023-08-15
Related CWE(s) CWE-287: Improper Authentication
Related Vendor(s) ivanti
Related Product(s) endpoint_manager_mobile
Exploitation Reported (CISA KEV) 2024-01-18
CVSS 3 Base Score 10.0 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References