critical Known exploitedREV. 01
CVE-2023-35082Ivanti EPMM / MobileIron Core — Unauthenticated API Access
An authentication bypass in Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core, lets an unauthenticated attacker reach restricted application programming interface (API) endpoints and drive the server that manages a fleet of mobile devices.
Read the risk
THE VITAL STATS- CVSS score
- 9.8/ 10 CVSS v3.1
- EPSS probability
- 100% Likelihood of exploitation
- Attack complexity
- Low Conditions needed to exploit
- Known exploited
- Yes — CISA KEV
- CVE published
- 2023-08-15
- Added to KEV
- 2024-01-18
- Exploit published
- Not recorded
- Confidence
- high
- Kill chain
- initial access
- MITRE ATT&CK
- T1190
- Severity
- critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attacker needsNetwork access to an Ivanti Endpoint Manager Mobile or MobileIron Core server running 11.10 or older. No credentials needed.
Behind the card
3 REFERENCES- 01CVE recordNVD recordnvd.nist.gov
- 02Vendor advisoryIvanti advisoryforums.ivanti.com
- 03CISACISA Known Exploited Vulnerabilities entrycisa.gov
Field-level provenanceTRACE THE SOURCES +
Which source supports each field, when it was retrieved, and who extracted it.
| Fields | Source | Retrieved | Extractor | Confidence |
|---|---|---|---|---|
| title, summary, cvss, severity, exploitation.attack_complexity, exploitation.prerequisites, exploitation.exploit_available, remediation.patch_available, references | nvd.nist.gov | 2026-08-07 | claude-code | high |
| exploitation.known_exploited, recommended_action | cisa.gov | 2026-08-07 | claude-code | high |
| epss | api.first.org | 2026-08-07 | claude-code | high |
Printing history
THE RECORD- r1Initial base card
First printing. This card has not been reprinted since publication.