Tag: Ivanti EPMM Vulnerability

U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM Vulnerability
News

U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM Vulnerability

A serious issue that has been fixed and affects Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core was added by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to its list of known exploited vulnerabilities (KEV) on Thursday. The agency stated that the flaw is being actively exploited in the field. Concerning CVE-2023-35082 (CVSS score: 9.8), this vulnerability is an authentication bypass that is a workaround for another vulnerability in the same solution that is being tracked as CVE-2023-35078 (CVSS score: 10.0). "If exploited, this vulnerability enables an unauthorized, remote (internet-facing) actor to potentially access users' personally identifiable information and make limited changes to the server read more U.S. Cybersecurity Agency Warns of Actively E...
Researchers Discover Bypass for Recently Patched Critical Ivanti EPMM Vulnerability
News

Researchers Discover Bypass for Recently Patched Critical Ivanti EPMM Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) customers are urged to update to the most recent version of the programme after security researchers found a workaround for a recently resolved actively exploited vulnerability. The vulnerability, which has been assigned the tracking number CVE-2023-35082 (CVSS score: 10.0), was found by Rapid7 and "allows unauthenticated attackers to access the API in older unsupported versions of MobileIron Core (11.2 and below)." Ivanti stated in a warning published on August 2, 2023 that if abused, the vulnerability might allow an unauthorised, remote (internet-facing) attacker to possibly access users' personally identifiable information and perform restricted server changes read more Researchers Discover Bypass for Recently Patched Critical Ivanti EPMM Vul...