{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2023-35081",
  "revision": 1,
  "title": "Ivanti mobile manager — an administrator writing anywhere",
  "summary": "A path traversal in Ivanti's mobile endpoint manager (EPMM) lets an authenticated administrator write files anywhere on the appliance. Chained with the authentication flaw published beside it, the administrator part stops being a barrier.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.2,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.63577,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2023-07-31",
    "prerequisites": "An administrator account, or the companion authentication flaw that supplies one."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "Ivanti EPMM >= 11.10.0.3",
      "Ivanti EPMM >= 11.9.1.2",
      "Ivanti EPMM >= 11.8.1.2"
    ]
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "execution",
  "recommended_action": "Upgrade to 11.10.0.3, 11.9.1.2 or 11.8.1.2, and close the authentication flaw it chains with in the same window — apart they are half a break-in each.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-35081",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2023-35081",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-35081",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35081",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US"
    }
  ],
  "published_at": "2023-08-03T18:15:11.303Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "ivanti",
    "epmm",
    "mdm",
    "path-traversal",
    "exploit-chain",
    "kev"
  ]
}
