CVE-2023-39335
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/11/2023
Last modified:
29/08/2024
Description
A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized access and potential misuse of user accounts and resources.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* | 11.9.0 (excluding) | |
| cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* | 11.10.0 (including) | 11.10.0.4 (excluding) |
| cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* | 11.11.0 (including) | 11.11.0.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



