Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/ivanti/endpoint-manager-mobile

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Ivanti heeft meerdere kwetsbaarheden verholpen in Ivanti Endpoint Manager Mobile.

Join the discussion

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.

Join the discussion

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

Join the discussion

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.

Join the discussion

OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution

Join the discussion

OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution

Join the discussion

CVE-2023-35078 is a critical authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows attackers to access restricted application functionality and resources without any authentication. The vulnerability has a CVSS score of 10, indicating maximum severity, with complete compromise of confidentiality, integrity, and availability possible. No user interaction or privileges are required to exploit this flaw, and it affects all versions of the product. While no public exploits are currently known, the vulnerability poses a significant risk to organizations using Ivanti EPMM for mobile device management. European organizations relying on this product for endpoint security could face unauthorized access, data breaches, and operational disruption. Immediate patching or mitigation is critical, though no patches are currently listed. Organizations should implement network-level restrictions, monitor for anomalous access, and consider compensating controls until a fix is available. Countries with high adoption of Ivanti EPMM and critical infrastructure reliance on mobile device management, such as Germany, the UK, France, and the Netherlands, are most at risk.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:github/ivanti/endpoint-manager-mobile
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses