Aller au contenu

Fiche vulnérabilité

CVE-2023-35081 : faille exploitée ivanti endpoint manager mobile (CVSS 7.2)

Description

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Oui, inscrite au catalogue CISA KEV
Publication
3 août 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • ivanti endpoint manager mobile

Correctif et mesures

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Références

Rechercher une autre vulnérabilité dans la base CVE