LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-35082: Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 18, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Feb 8, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-35082 to its Known Exploited Vulnerabilities catalog on Jan 18, 2024, with a federal patch deadline of Feb 8, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the…

CVE-2023-35082 is an authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core. It allows unauthorized users to reach restricted functionality or resources without proper authentication. Because these products manage mobile devices and enterprise access, successful abuse can give attackers a foothold into device fleets, configuration data, and related infrastructure. CISA notes known ransomware use of this vulnerability, so rapid identification and remediation matter for any organization running the software.

How it works

The weakness is classified as CWE-287 (Improper Authentication). In products of this class, authentication checks that should gate access to administrative or sensitive interfaces fail under certain conditions. An attacker who can reach the affected service may bypass those checks and interact with restricted functionality or resources as if authenticated. Exact request patterns, endpoints, or preconditions are not detailed here; defenders must confirm the precise mechanics and any required conditions against the vendor advisory. The practical outcome is unauthorized access that can lead to further compromise of the mobile-device management environment.

Am I affected? How to find it in your systems

Ivanti EPMM (formerly MobileIron Core) typically runs as an on-premises or appliance-based mobile device management (MDM) platform that enrolls, configures, and secures corporate mobile devices. Inventory steps include:

For signs of exploitation, examine authentication and access logs for unexpected successful access to restricted resources from unauthenticated or unusual sources, anomalous administrative actions, or sudden changes to device enrollment or policy. Correlate with network telemetry showing connections to the management interface from unexpected external or internal hosts. Absence of clear indicators does not prove safety; treat any unpatched instance as potentially exposed.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation exactly as described in the Ivanti advisory for CVE-2023-35082. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. After patching:

Document the change and re-scan to confirm the vulnerability is no longer present.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited authentication-bypass vulnerabilities, especially those with known ransomware use, frequently lead to broader breaches. Assume that any unpatched instance reachable by an attacker may have been accessed. Review logs for indicators of compromise, isolate affected systems, and follow your incident-response plan, including credential resets and forensic preservation. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Endpoint Manager Mobile (EPMM) and MobileIron Core
WeaknessCWE-287
Added to CISA KEVJan 18, 2024
Federal patch deadlineFeb 8, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities