VDB

GSD-2023-35082

GSD-2023-35082 PUBLISHED CVSS 10 CRITICAL

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

Risk Scores

CVSS 3.0
10
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
IvantiEPMM11.10

Timeline

  • Jul 26, 2023 CVE Published
  • Jan 18, 2024 PoC Published
  • Jan 22, 2024 PoC Published
  • Oct 26, 2024 PoC Published
  • Oct 27, 2024 PoC Published
  • Oct 30, 2024 PoC Published
  • Oct 31, 2024 PoC Published
  • Nov 1, 2024 PoC Published
  • Nov 2, 2024 PoC Published
  • Nov 5, 2024 PoC Published
  • Nov 7, 2024 PoC Published
  • Nov 9, 2024 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›