Skip to content
COOEY

EXPOSURES › CVE-2023-35081

CVE-2023-35081

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-07-31 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-35081 ↗
⌖ EXPLOITED IN THE WILD SHAME 68/100 exploited-in-wildunpatched

An authenticated administrator of Ivanti Endpoint Manager Mobile (EPMM) can write malicious files to the server via a path traversal vulnerability, potentially bypassing access controls and enabling further compromise.

Ivanti EPMM's path traversal vulnerability (CVE-2023-35081) allows authenticated administrators to write files, often exploited in conjunction with CVE-2023-35078 to bypass authentication. DIB organizations using EPMM face potential data breaches, compliance failures (CMMC/NIST 800-171), and system compromise; immediate patching and access control review are critical.

Shame score — The vulnerability's exploitation alongside an authentication bypass flaw demonstrates a significant failure in access control design and implementation, compounded by repeated targeting by sophisticated threat actors.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable).

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized