CVE-2023-35082
KEV ransomwarelargeAuthentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core
CISA: Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) and its predecessor MobileIron Core contain an improper authentication flaw (CWE-287) that allows an unauthorized user to bypass authentication and access restricted functionality or resources of the application. It is triggered by sending unauthenticated requests to the affected appliance, with no valid credentials or user interaction required. A successful attacker gains access to protected MDM functionality and resources on the server, which has been leveraged in broader intrusions, including ransomware operations. Any organization running EPMM or MobileIron Core, particularly with the management interface exposed to the internet, is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-18 with known ransomware use, and EPSS assigns it a ~100% probability of exploitation within 30 days (100th percentile).
What to do: Apply Ivanti's patched releases immediately per the vendor advisory, or discontinue use if mitigations are unavailable, as required by CISA's KEV listing. Because the flaw has known ransomware use, review EPMM/MobileIron Core logs for unauthenticated access to restricted functionality and hunt for signs of follow-on compromise. Prioritize patching internet-facing instances and limit exposure of the management interface until updates are applied.
| Ivanti Endpoint Manager Mobile (EPMM) | — |
| Ivanti MobileIron Core | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.
- Affected
- Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- ivanti
- Products
- endpoint manager mobile
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H