ZeroHour

CVE-2023-35081

KEVlarge

Authenticated Path Traversal in Ivanti Endpoint Manager Mobile (EPMM)

CISA: Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability

CVSS 3.1
7.2 high
EPSS
64%p99
Published
()
KEV added
AI analysis

CVE-2023-35081 is a path traversal (CWE-22) vulnerability in Ivanti Endpoint Manager Mobile (EPMM), the on-premises mobile device management appliance formerly known as MobileIron Core. It is triggered when an authenticated administrator submits crafted path input, allowing the attacker to write arbitrary files onto the appliance outside intended directories. Because arbitrary files can be written to the appliance, the flaw can be leveraged to further compromise the device, and public reporting indicates it was used in real-world attacks alongside a previously disclosed EPMM authentication bypass. Organizations running EPMM 11.8.x, 11.9.x, or 11.10.x prior to the fixed builds are affected. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-31, attacks on Norwegian government entities have been reported, and no public PoC is known.

What to do: Upgrade EPMM to 11.10.0.3, 11.9.1.2, or 11.8.1.2 for the 11.10.x, 11.9.x, and 11.8.x branches respectively, and treat this as urgent given the CISA KEV listing. Until patched, restrict internet-facing access to the EPMM appliance and review the device for unexpected or newly written files and other signs of compromise. Administrators should also confirm they are not exposed via chaining with the previously disclosed EPMM authentication bypass used in the same attacks.

Affected
Ivanti Endpoint Manager Mobile (EPMM)11.10.x before 11.10.0.3
Ivanti Endpoint Manager Mobile (EPMM)11.9.x before 11.9.1.2
Ivanti Endpoint Manager Mobile (EPMM)11.8.x before 11.8.1.2
Estimated exposure
largeon the order of tens of thousands of EPMM appliance deployments worldwide (exact internet-exposed count unknown) — EPMM is a dedicated on-premises MDM appliance used mainly by large enterprises and government agencies rather than mass-market consumers, and the July 2023 EPMM exploitation wave (including attacks on Norwegian government entities) was…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.

CISA Known Exploited Vulnerability
Affected
Ivanti Endpoint Manager Mobile (EPMM)
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
ivanti
Products
endpoint manager mobile
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news