CVE-2023-39335
CRITICALIvanti Endpoint Manager Mobile < 11.9.0 - Unauthenticated User Impersonation during Device Enrollment
Title source: llmDescription
A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized access and potential misuse of user accounts and resources.
References (1)
Core 1
Core References
Scores
CVSS v3
9.8
EPSS
0.0162
EPSS Percentile
82.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (1)
ivanti/endpoint_manager_mobile
< 11.9.0
Published
Nov 15, 2023
Tracked Since
Feb 18, 2026