References https://hub.ivanti.com/s/article/CVE-2023-35082-Remote-Unauthenticated-API-Access-Vulnerability-in-MobileIron-Core-11-2-and-older https://nvd.nist.gov/vuln/detail/cve-2023-35082 https://www.rapid7.com/blog/post/2023/08/02/cve-2023-35082-mobileiron-core-unauthenticated-api-access-vulnerability/ https://www.ivanti.com/blog/cve-2023-35082-vulnerability-affecting-epmm-and-mobileiron-core https://research.splunk.com/web/e03edeba-4942-470c-a664-27253f3ad351/ https://www.cve.org/CVERecord?id=CVE-2023-35082 https://www.sentinelone.com/vulnerability-database/cve-2023-35082/ https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35082.yaml https://www.rapid7.com/db/vulnerabilities/ivantiepmm-cve-2023-35082/ https://threatprotect.qualys.com/2023/08/03/ivanti-endpoint-manager-mobile-epmm-remote-unauthenticated-api-access-vulnerability-cve-2023-35082/ https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-213a https://www.helpnetsecurity.com/2024/01/19/exploited-cve-2023-35082/ https://cert.360.cn/warning/detail?id=65ae53dec09f255b91b17cc1 https://zhuanlan.zhihu.com/p/679132356 https://digital.nhs.uk/cyber-alerts/2024/cc-4440 https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2024-010/
Related VulnerabilitiesPoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code InjectionPoCCVE-2026-10520: Ivanti Sentry - OS Command InjectionIvanti Sentry存在操作系统命令注入漏洞(CVE-2026-10520)Ivanti Sentry /mics/api/v2/sentry/mics-config/handleMessage 命令执行漏洞(CVE-2026-10520)Ivanti EPMM /mifs/rs/api/v2/featureusage 命令执行漏洞(CVE-2025-4427)PoCIvanti Endpoint Manager /RemoteControlAuth/api/Auth 权限绕过漏洞(CVE-2026-1603)Ivanti Endpoint Manager 权限管理不当漏洞PoCCVE-2026-1603: Ivanti Endpoint Manager - Authentication BypassIvanti Endpoint Manager Mobile /mifs/c/appstore/fob/3/5/sha256 命令执行漏洞(CVE-2026-1281/CVE-2026-1340)Ivanti Endpoint Manager Mobile 未授权 代码注入漏洞Ivanti多个产品跨站请求伪造漏洞(CVE-2025-8711)(CVE-2025-8712)Ivanti产品权限验证不足漏洞