CVE-2023-35078
CRITICAL KEV RANSOMWARE NUCLEIIvanti Endpoint Manager Mobile < 11.8.1.1 - Authentication Bypass
Title source: ruleDescription
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
Exploits (7)
nomisec
WORKING POC
118 stars
by vchan-in · infoleak
https://github.com/vchan-in/CVE-2023-35078-Exploit-POC
nomisec
STUB
1 stars
by emanueldosreis · infoleak
https://github.com/emanueldosreis/nmap-CVE-2023-35078-Exploit
Nuclei Templates (1)
Ivanti Endpoint Manager Mobile (EPMM) - Authentication Bypass
CRITICALVERIFIEDby parth,pdresearch
Shodan:
http.favicon.hash:362091310 || http.favicon.hash:"362091310"
FOFA:
icon_hash="362091310"
References (5)
Scores
CVSS v3
9.8
EPSS
0.9444
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2023-07-25
VulnCheck KEV
2023-07-24
InTheWild.io
2023-07-25
ENISA EUVD
EUVD-2023-39113
Ransomware Use
Confirmed
CWE
CWE-287
Status
published
Products (1)
ivanti/endpoint_manager_mobile
< 11.8.1.1
Published
Jul 25, 2023
KEV Added
Jul 25, 2023
Tracked Since
Feb 18, 2026