CVE-2023-35085 is an integer overflow vulnerability affecting all UniFi Access Points version 6.5.50 and earlier and all UniFi Switches version 6.5.32 and earlier, excluding the USW Flex Mini. According to the provided vendor description, the issue is present when SNMP Monitoring is enabled with default settings, and successful exploitation could allow remote code execution. Specific vulnerable functions or code paths are not provided in the available content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains three Python scripts and a README, all focused on exploiting CVE-2023-35085, a critical unauthenticated API access vulnerability in Ivanti EPMM (MobileIron Core). The main exploit scripts are: 1. EXP_reverse_shell-CVE-2023-35085.py: Attempts to exploit the vulnerability by sending command injection payloads to several known API endpoints (such as /mifs/rest/api/v2/command/exec, /mifs/aad/api/v2/config/exec, /api/v2/system/shell, and /mifs/aad/api/v2/ping). It generates multiple types of reverse shell payloads (bash, python, perl, netcat) and tries to execute them on the target, aiming to establish a reverse shell connection to the attacker's machine. 2. EXP_webshell-CVE-2023-35085.py: Exploits the same vulnerability to upload various types of webshells (PHP, JSP, ASP, and disguised files) to common web-accessible directories on the target. If successful, it provides a persistent webshell for remote command execution via HTTP requests. 3. POC-CVE-2023-35085.py: A proof-of-concept script that checks if the target is vulnerable by attempting unauthenticated access to specific API endpoints and reporting the results. The scripts are operational and provide both exploitation and verification capabilities. They require the attacker to specify the target URL and, for the reverse shell, the attacker's IP and port. The README notes that the scripts were generated with AI assistance and may not be fully reliable, but the code structure and payloads are consistent with real-world exploitation techniques for this vulnerability. Notable endpoints targeted include several Ivanti EPMM API paths, and the webshell script attempts to write files to a variety of likely web directories. The attack vector is network-based, requiring access to the target's API endpoints over HTTP(S).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.