VDB
CVE-2023-35082
CVE-2023-35082
PUBLISHED
KEV
Es existiert eine Schwachstelle in Ivanti Endpoint Manager Mobile. Diese ist auf einen Fehler in der API für Zugriffe zurückzuführen. Ein entfernter, anonymer Angreifer kann diese Schwachstelle ausnutzen, um Dateien zu manipulieren oder Informationen offenzulegen.
EPSS 94.40% · 100.0th percentile
Risk Scores
EPSS Score
94.40%
100.0th percentile
Timeline
- Jan 20, 1970 VulnCheck XDB Entry
- Jul 26, 2023 CVE Published
- Aug 3, 2023 PoC Published
- Aug 3, 2023 Nuclei Template
- Aug 3, 2023 Fix Commit
- Aug 16, 2023 EPSS Score
- Aug 22, 2023 EPSS Score
- Sep 22, 2023 EPSS Score
- Oct 20, 2023 EPSS Score
- Nov 15, 2023 VulnCheck KEV Exploitation
- Nov 16, 2023 VulnCheck KEV Exploitation
- Nov 18, 2023 VulnCheck KEV Exploitation
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1958.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1958 advisory
- https://forums.ivanti.com/s/article/CVE-2023-35082-Remote-Unauthenticated-API-Access-Vulnerability-in-MobileIron-Core-11-2-and-older advisory
- https://www.cisa.gov/news-events/alerts/2024/01/18/cisa-adds-one-known-exploited-vulnerability-catalog exploit