.. / CVE-2023-35078

Exploit for Ivanti Endpoint Manager Mobile (EPMM) - Authentication Bypass (CVE-2023-35078)

Description:

Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core, through 11.10 allows remote attackers to obtain PII, add an administrative account, and change the configuration because of an authentication bypass, as exploited in the wild in July 2023. A patch is available.

Nuclei Template

View the template here CVE-2023-35078.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2023/CVE-2023-35078.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2023-35078
https://www.ivanti.com/blog/cve-2023-35078-new-ivanti-epmm-vulnerability
https://www.cisa.gov/news-events/alerts/2023/07/24/ivanti-releases-security-updates-endpoint-manager-mobile-epmm-cve-2023-35078
https://forums.ivanti.com/s/article/KB-Remote-unauthenticated-API-access-vulnerability-CVE-2023-35078
https://help.ivanti.com/mi/help/en_us/CORE/11.2.0.0/dmgw/DMGfiles/Join_Azure_and_MobileIro.htm
https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability