CVE-2023-39335
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized access and potential misuse of user accounts and resources.
Se identificó una vulnerabilidad de seguridad en las versiones 11.10, 11.9 y 11.8 y anteriores de EPMM, lo que permite que un actor de amenazas no autenticado se haga pasar por cualquier usuario existente durante el proceso de inscripción del dispositivo. Este problema plantea un riesgo de seguridad importante, ya que permite el acceso no autorizado y el posible uso indebido de cuentas y recursos de usuario.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-07-28 CVE Reserved
- 2023-11-14 CVE Published
- 2024-08-29 CVE Updated
- 2024-11-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://forums.ivanti.com/s/article/CVE-2023-39335?language=en_US | 2023-11-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ivanti Search vendor "Ivanti" | Endpoint Manager Mobile Search vendor "Ivanti" for product "Endpoint Manager Mobile" | < 11.9.0 Search vendor "Ivanti" for product "Endpoint Manager Mobile" and version " < 11.9.0" | - |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Endpoint Manager Mobile Search vendor "Ivanti" for product "Endpoint Manager Mobile" | >= 11.10.0 < 11.10.0.4 Search vendor "Ivanti" for product "Endpoint Manager Mobile" and version " >= 11.10.0 < 11.10.0.4" | - |
Affected
| ||||||
Ivanti Search vendor "Ivanti" | Endpoint Manager Mobile Search vendor "Ivanti" for product "Endpoint Manager Mobile" | >= 11.11.0 < 11.11.0.2 Search vendor "Ivanti" for product "Endpoint Manager Mobile" and version " >= 11.11.0 < 11.11.0.2" | - |
Affected
|