← Browse

CVE-2023-35081

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
63.6%
99.2th percentile
CISA KEV
Listed
Added 2023-07-31 · patch by 2023-08-21
Weakness / dates
Published — · modified —

Timeline

Description

Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable).

Official: NVD · CVE.org