EXPOSURES › CVE-2023-35081
CVE-2023-35081
HIGH ⌖ ON CISA KEV · EXPLOITEDAn authenticated administrator of Ivanti Endpoint Manager Mobile (EPMM) can write malicious files to the server via a path traversal vulnerability, potentially bypassing access controls and enabling further compromise.
Ivanti EPMM's path traversal vulnerability (CVE-2023-35081) allows authenticated administrators to write files, often exploited in conjunction with CVE-2023-35078 to bypass authentication. DIB organizations using EPMM face potential data breaches, compliance failures (CMMC/NIST 800-171), and system compromise; immediate patching and access control review are critical.
Shame score — The vulnerability's exploitation alongside an authentication bypass flaw demonstrates a significant failure in access control design and implementation, compounded by repeated targeting by sophisticated threat actors.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable).
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |