CVE-2023-35078
CVE-2023-35078 is a critical authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that lets unauthenticated attackers access restricted functions or data. It has a CVSS score of 9.8 and is known exploitation. CISA advises applying vendor-provided mitigations or discontinuing use of the product if mitigations are not available.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Ivanti Endpoint Manager Mobile (EPMM)
Real-world impact
Unauthorized access to sensitive application functionality and data, potentially leading to full compromise.
Why this severity
CVSS 9.8 (Critical) reflects network‑reachable, low‑complexity attack with no privileges or user interaction required, impacting confidentiality, integrity, and availability.
What to do about it
- ›Apply mitigations per Ivanti vendor instructions.
- ›If mitigations cannot be applied, discontinue use of Ivanti EPMM.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
CISA KEV required action
Timeline
- Jul 25, 2023 · Jul 25, 2023Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jul 25, 2023 · Jul 25, 2023PublishedDisclosed and added to the National Vulnerability Database.
- Aug 15, 2023 · Aug 15, 2023CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 5, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- forums.ivanti.com/s/article/CVE-2023-35078-Re…vendor advisory
- forums.ivanti.com/s/article/KB-Remote-unauthe…exploitvendor advisory
- cisa.gov/news-events/alerts/2023/07/…third party advisoryus government resource
- ivanti.com/blog/cve-2023-35078-new-iva…vendor advisory
- cisa.gov/known-exploited-vulnerabili…us government resource