Page 1 of 1

CISA: Critical Ivanti auth bypass bug now actively exploited

Posted: Fri Jan 19, 2024 12:40 pm
by rbc
CISA warns that a critical authentication bypass vulnerability in Ivanti's Endpoint Manager Mobile (EPMM) and MobileIron Core device management software (patched in August 2023) is now under active exploitation.

Tracked as CVE-2023-35082, the flaw is a remote unauthenticated API access vulnerability affecting all versions of EPMM 11.10, 11.9, and 11.8 and MobileIron Core 11.7 and below,.

Successful exploitation provides attackers access to personally identifiable information (PII) of mobile device users and can let them backdoor compromised servers when chaining the bug with other flaws.
[...]
CISA: Critical Ivanti auth bypass bug now actively exploited