CVE-2023-35078

CRITICAL KEV RANSOMWARE NUCLEI

Ivanti Endpoint Manager Mobile < 11.8.1.1 - Authentication Bypass

Title source: rule

Description

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

Exploits (7)

nomisec WORKING POC 118 stars
by vchan-in · infoleak
https://github.com/vchan-in/CVE-2023-35078-Exploit-POC
nomisec WORKING POC 5 stars
by raytheon0x21 · poc
https://github.com/raytheon0x21/CVE-2023-35078
nomisec SCANNER 5 stars
by lager1 · poc
https://github.com/lager1/CVE-2023-35078
nomisec WORKING POC 1 stars
by 0nsec · remote
https://github.com/0nsec/CVE-2023-35078
nomisec STUB 1 stars
by emanueldosreis · infoleak
https://github.com/emanueldosreis/nmap-CVE-2023-35078-Exploit
nomisec SCANNER
by Blue-number · remote
https://github.com/Blue-number/CVE-2023-35078
nomisec SCANNER
by synfinner · infoleak
https://github.com/synfinner/CVE-2023-35078

Nuclei Templates (1)

Ivanti Endpoint Manager Mobile (EPMM) - Authentication Bypass
CRITICALVERIFIEDby parth,pdresearch
Shodan: http.favicon.hash:362091310 || http.favicon.hash:"362091310"
FOFA: icon_hash="362091310"

Scores

CVSS v3 9.8
EPSS 0.9444
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2023-07-25
VulnCheck KEV 2023-07-24
InTheWild.io 2023-07-25
ENISA EUVD EUVD-2023-39113
Ransomware Use Confirmed
CWE
CWE-287
Status published
Products (1)
ivanti/endpoint_manager_mobile < 11.8.1.1
Published Jul 25, 2023
KEV Added Jul 25, 2023
Tracked Since Feb 18, 2026