VDB
GSD-2023-35082
GSD-2023-35082
PUBLISHED
CVSS 10 CRITICAL
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.
Risk Scores
CVSS 3.0
10
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | EPMM | 11.10 |
Timeline
- Jul 26, 2023 CVE Published
- Jan 18, 2024 PoC Published
- Jan 22, 2024 PoC Published
- Oct 26, 2024 PoC Published
- Oct 27, 2024 PoC Published
- Oct 30, 2024 PoC Published
- Oct 31, 2024 PoC Published
- Nov 1, 2024 PoC Published
- Nov 2, 2024 PoC Published
- Nov 5, 2024 PoC Published
- Nov 7, 2024 PoC Published
- Nov 9, 2024 PoC Published