Executive brief
Ivanti Sentry (formerly MobileIron Sentry) contains an authentication bypass vulnerability in the MICS Admin Portal. The flaw arises from an insufficiently restrictive Apache HTTPD configuration, allowing unauthenticated attackers to bypass security controls on the administrative interface.
Affected products
- Ivanti MobileIron Sentry (Ivanti Sentry) 9.18.0 and below
Timeline
- 2023-08-21: disclosed
- 2023-08-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-08-22: advisory