Junglewise Threat Intelligence

CVE-2023-38035: Ivanti Sentry Authentication Bypass Vulnerability

CVE-2023-38035 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-08-22

Technologies: Ivanti Sentry. Vendors: Ivanti.

Executive brief

Ivanti Sentry (formerly MobileIron Sentry) contains an authentication bypass vulnerability in the MICS Admin Portal. The flaw arises from an insufficiently restrictive Apache HTTPD configuration, allowing unauthenticated attackers to bypass security controls on the administrative interface.

Affected products

  • Ivanti MobileIron Sentry (Ivanti Sentry) 9.18.0 and below

Timeline

  • 2023-08-21: disclosed
  • 2023-08-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-08-22: advisory

Related threats