Vulnerability record · CVE-2023-35081 · published 3 August 2023
CVE-2023-35081: Ivanti EPMM path traversal allows authenticated admin arbitrary file write
Ivanti · Endpoint Manager Mobile
Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal flaw (CWE-22) in versions 11.10.x before 11.10.0.3, 11.9.x before 11.9.1.2, and 11.8.x before 11.8.1.2. An authenticated administrator can write arbitrary files onto the appliance. Because the affected product is a mobile device management server, file write access to the appliance is a serious foothold concern.
Description
A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA KEV with very high EPSS, but exploitation requires an authenticated administrator account, which limits who can trigger it.
What it is
Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal flaw (CWE-22) in versions 11.10.x before 11.10.0.3, 11.9.x before 11.9.1.2, and 11.8.x before 11.8.1.2. An authenticated administrator can write arbitrary files onto the appliance. Because the affected product is a mobile device management server, file write access to the appliance is a serious foothold concern.
Impact
An attacker with administrator access gains the ability to write arbitrary files on the EPMM appliance, which can lead to code execution or full compromise of the management server. That server typically holds control over managed mobile devices and related credentials.
Attack surface
Reachable over the network (CVSS vector AV:N) with low attack complexity, but it requires high privileges (PR:H), meaning a valid administrator account on EPMM. No user interaction is needed (UI:N).
Exploitation
It is listed in CISA's Known Exploited Vulnerabilities catalog with a 2023-07-31 addition date, and EPSS gives a 30-day probability of 0.63577 (99.2nd percentile), indicating active exploitation is expected. No ransomware campaign use is documented in the record.
What to do
- Upgrade EPMM to 11.10.0.3, 11.9.1.2, or 11.8.1.2 (or later) as directed by the vendor advisory.
- If patching is not immediately possible, apply the vendor's documented mitigations or discontinue use of the product per CISA's required action.
- Restrict and audit administrator accounts on EPMM; remove unused or shared admin credentials.
- Limit network exposure of the EPMM administrative interface to trusted management networks.
- Monitor for unexpected file changes on the EPMM appliance after patching.
Detection
- Review EPMM appliance file system and logs for unexpected or newly written files, especially outside expected directories.
- Alert on administrator logins or admin-level actions from unusual source IPs or at unusual times.
- Correlate EPMM admin activity with outbound connections or subsequent process execution on the appliance.
- Track EPMM versions in inventory and flag any host still below the fixed builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-35081 to the Known Exploited Vulnerabilities catalog on 31 July 2023 as "Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 21 August 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US | Vendor Advisory |
| https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-35081 | US Government Resource |
Track CVE-2023-35081 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-35081), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.