Impact
Ivanti Endpoint Manager Mobile (EPMM) versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1 implement improper certificate validation, a certificate validation weakness (CWE‑295) that allows a remote unauthenticated attacker to enroll a device that belongs to a restricted set of unenrolled devices. This flaw exposes details about the EPMM appliance and compromises the integrity of the newly enrolled device identity, leading to sensitive information being disclosed and potential misuse of the device within the mobile management environment.
Affected Systems
The vulnerability affects Ivanti Endpoint Manager Mobile. All devices running versions prior to 12.6.1.1, 12.7.0.1, or 12.8.0.1 are susceptible until an update is applied. No other vendors or products are known to be impacted.
Risk and Exploitability
The CVSS score of 7.4 indicates a high level of risk. EPSS score is not available, so the precise exploitation probability cannot be quantified. The flaw allows remote unauthenticated interaction as part of the enrollment process, which exposes appliance details and allows integrity compromise of the newly enrolled device identity. It is not listed in CISA KEV, suggesting no publicly reported exploits yet.
OpenCVE Enrichment