Critical severity9.8CISA KEVNVD Advisory· Published Jul 25, 2023· Updated Aug 5, 2026
CVE-2023-35078
CVE-2023-35078
Description
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*range: <11.8.1.1
- (no CPE)
- (no CPE)range: 11.10
Patches
Vulnerability mechanics
References
5- forums.ivanti.com/s/article/KB-Remote-unauthenticated-API-access-vulnerability-CVE-2023-35078nvdExploitVendor Advisory
- forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerabilitynvdVendor Advisory
- www.cisa.gov/news-events/alerts/2023/07/24/ivanti-releases-security-updates-endpoint-manager-mobile-epmm-cve-2023-35078nvdThird Party AdvisoryUS Government Resource
- www.ivanti.com/blog/cve-2023-35078-new-ivanti-epmm-vulnerabilitynvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.