Lucene search

K
cveHackeroneCVE-2023-39335
HistoryNov 15, 2023 - 12:15 a.m.

CVE-2023-39335

2023-11-1500:15:08
CWE-269
hackerone
web.nvd.nist.gov
30
cve-2023-39335
security vulnerability
epmm
unauthorized access
user impersonation
device enrollment
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.001

Percentile

39.1%

A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized access and potential misuse of user accounts and resources.

Affected configurations

Nvd
Vulners
Node
ivantiendpoint_manager_mobileRange<11.9.0
OR
ivantiendpoint_manager_mobileRange11.10.011.10.0.4
OR
ivantiendpoint_manager_mobileRange11.11.011.11.0.2
VendorProductVersionCPE
ivantiendpoint_manager_mobile*cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "vendor": "Ivanti",
    "product": "EPMM",
    "versions": [
      {
        "version": "11.10.0.0",
        "status": "affected",
        "lessThanOrEqual": "11.10.0.0",
        "versionType": "semver"
      },
      {
        "version": "11.9.0.0",
        "status": "affected",
        "lessThanOrEqual": "11.9.0.0",
        "versionType": "semver"
      },
      {
        "version": "11.8.0.0",
        "status": "affected",
        "lessThanOrEqual": "11.8.0.0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.001

Percentile

39.1%

Related for CVE-2023-39335