Ivanti released a security update to fix a critical vulnerability affecting Ivanti Endpoint Manager Mobile (EPMM) version 11.2 and older, formerly known as MobileIron Core.
The addressed vulnerability could allow the remote attacker to gain access to specific API paths without requiring authentication, and disclose information related to personally identifiable information (PII) and this vulnerability could be chained with CVE-2023-35081 to allow the remote attacker to write malicious webshell files to the appliance.
Remote Unauthenticated API Access Vulnerability (CVE-2023-35082):
It should be highlighted that Ivanti has confirmed that Ivanti MobileIron Core 11.2 has been out of support since March 15, 2022, so Ivanti encourages customers to upgrade to the latest version of Ivanti Endpoint Manager Mobile (EPMM) to protect their environment from threats.
CVE-2023-35082
The enterprise should upgrade to the latest version of Ivanti Endpoint Manager Mobile (EPMM) as soon as the testing phase is completed.
Cookie | Duration | Description |
---|---|---|
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |