---
cve: "CVE-2023-35082"
severity: "CRITICAL"
cvss: 10.0
epss: "100%"
vendor: "Ivanti"
kev: true
exploited: true
published: "2023-08-15 16:15:11"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-05T20:26:34+02:00"
---

# CVE-2023-35082

> 10.0 CRITICAL · ⚠️ CISA KEV (961 Tage) · 🔓 Exploited

## Beschreibung

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

## CVSS-Vektor

```
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://forums.ivanti.com/s/article/CVE-2023-35082-Remote-Unauthenticated-API-Access-Vulnerability-in-MobileIron-Core-11-2-and-older?language=en_US>
- <https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-35082>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-35082) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
