ZeroHour

CVE-2023-35082

KEV ransomwarelarge

Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core

CISA: Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

Ivanti Endpoint Manager Mobile (EPMM) and its predecessor MobileIron Core contain an improper authentication flaw (CWE-287) that allows an unauthorized user to bypass authentication and access restricted functionality or resources of the application. It is triggered by sending unauthenticated requests to the affected appliance, with no valid credentials or user interaction required. A successful attacker gains access to protected MDM functionality and resources on the server, which has been leveraged in broader intrusions, including ransomware operations. Any organization running EPMM or MobileIron Core, particularly with the management interface exposed to the internet, is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-18 with known ransomware use, and EPSS assigns it a ~100% probability of exploitation within 30 days (100th percentile).

What to do: Apply Ivanti's patched releases immediately per the vendor advisory, or discontinue use if mitigations are unavailable, as required by CISA's KEV listing. Because the flaw has known ransomware use, review EPMM/MobileIron Core logs for unauthenticated access to restricted functionality and hunt for signs of follow-on compromise. Prioritize patching internet-facing instances and limit exposure of the management interface until updates are applied.

Affected
Ivanti Endpoint Manager Mobile (EPMM)
Ivanti MobileIron Core
Estimated exposure
largetens of thousands of enterprise and government deployments, with only a few thousand servers directly internet-exposed — The legacy MobileIron platform claimed tens of thousands of customer organizations before Ivanti's acquisition, and public internet scans during the 2023 EPMM incidents found only a few thousand EPMM servers directly exposed, implying an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

CISA Known Exploited Vulnerability
Affected
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
ivanti
Products
endpoint manager mobile
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news