CVE-2023-35081: Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability
High severity, CVSS 7.2. Actively exploited: in CISA KEV since 2023-07-31. EPSS: 63.6% chance of exploitation in the next 30 days.
A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.
Affected products
- Ivanti Endpoint Manager Mobile: from 11.8.0, before 11.8.1.2 (fixed in 11.8.1.2); from 11.9.0, before 11.9.1.2 (fixed in 11.9.1.2); from 11.10.0, before 11.10.0.3 (fixed in 11.10.0.3)
Published 2023-08-03. Last modified 2026-06-17.