S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2023-35082 Scanner

Detects 'Authentication Bypass' vulnerability in Ivanti EPMM affects v. 11.10 and before.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-35082
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
EPMMby Ivanti
11.10
Updated Aug 22, 2026View on NVD →
Detail

Ivanti Endpoint Manager (EPM) is a platform widely used for the purpose of endpoint management, which is the process of securing and managing devices connected to a network. These devices can include computers, mobile devices, and other endpoints. Ivanti EPM is an all-in-one solution designed to simplify the management of endpoints and automate IT tasks. The platform enables efficient software distribution, remote control of endpoints, patch management, and asset management across multiple platforms.

CVE-2023-35082 is an authentication bypass vulnerability discovered in Ivanti EPM 11.10 and older versions. This vulnerability allows unauthorized users to gain access to restricted functionalities and resources of the application without proper authentication. Attackers can exploit this vulnerability to perform malicious activities such as executing unauthorized administrative actions, compromising sensitive data, and deploying malware across the network.

When exploited, this vulnerability can ultimately lead to the complete compromise of an organization's network. Attackers with unauthorized access can steal valuable data leading to financial loss, legal liabilities, and reputational damage. Additionally, an attacker with access to the Ivanti EPM platform can also execute unauthorized administrative actions and carry out destructive activities such as deleting important files and data.

Thanks to the pro features of s4e.io, individuals can quickly and easily learn about vulnerabilities in their digital assets and take steps to secure them. The platform provides comprehensive cybersecurity solutions to prevent and detect potential security risks, protecting both individuals and organizations from attacks and data breaches. By staying informed on security risks and taking proactive measures to mitigate them, users can ensure that their digital assets remain safe and secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended to take the following precautions:

  • Upgrade to the latest version of Ivanti EPM.
  • Implement two-factor authentication for all users.
  • Restrict access to Ivanti EPM to only authorized personnel and remove unnecessary user accounts.
  • Monitor the Ivanti EPM network and log activity to detect and prevent unauthorized access.
  • Regularly conduct security audits and vulnerability scans.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.