LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-35078: Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 25, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Aug 15, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-35078 to its Known Exploited Vulnerabilities catalog on Jul 25, 2023, with a federal patch deadline of Aug 15, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with…

CVE-2023-35078 is an authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM), previously known as MobileIron Core. It allows unauthenticated access to specific API paths on a vulnerable system.

This matters because an attacker who reaches those paths can obtain personally identifiable information such as names, phone numbers, and other mobile device details, and can also make configuration changes including installing software and modifying security profiles on registered devices. The vulnerability has known ransomware use, so organizations running EPMM should treat discovery and remediation as high priority.

How it works

The flaw is classified as CWE-287 (improper authentication). In practice, the product fails to enforce authentication properly on certain API paths. An attacker with network access to a vulnerable EPMM instance can therefore interact with those paths without valid credentials. Once there, the attacker can read PII belonging to users and devices managed by the system, and can issue configuration changes that affect registered mobile endpoints. Exact API paths, request formats, and any additional preconditions are not detailed in the available summary; defenders must confirm those specifics against the vendor advisory rather than relying on general descriptions of this weakness class.

Am I affected? How to find it in your systems

Ivanti EPMM (and its earlier MobileIron Core branding) is typically deployed as an on-premises or privately hosted mobile device management server that enrolls and controls enterprise smartphones and tablets. It is commonly found in environments that centralize mobile policy, app distribution, and device inventory.

How to remediate

The primary action is to apply the mitigations or updates published by the vendor. CISA’s required action is to apply mitigations per vendor instructions or to discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls that limit reachability and increase detection.

If your data may have been exposed

Actively exploited authentication-bypass vulnerabilities of this type can result in unauthorized access to PII and subsequent ransomware activity. If logs or other evidence suggest the vulnerable APIs were reached, treat the incident as a potential breach: preserve forensic data, notify appropriate internal stakeholders, and follow your organization’s incident-response and regulatory notification procedures. Individuals concerned about personal exposure can run a free exposure scan of their email address against known breach data sets to check whether their information has appeared in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Endpoint Manager Mobile (EPMM)
WeaknessCWE-287
Added to CISA KEVJul 25, 2023
Federal patch deadlineAug 15, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities