SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-35081

Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability

KEVHIGH 7.2EPSS 63.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 21 August 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
63.58% probability · 99th percentile
CISA KEV
Listed 31 July 2023 · due 21 August 2023
Weakness
CWE-22
Affected
ivanti/endpoint manager mobile
Source
support@hackerone.com

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2023-35081

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.