CVE-2023-38035: Ivanti Sentry Authentication Bypass Vulnerability
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
Other sources
Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
— CISA
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-38035?
CVE-2023-38035 is a security vulnerability in the MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which allows an attacker to bypass authentication controls on the administrative interface.
How severe is the CVE-2023-38035 vulnerability?
The severity of the CVE-2023-38035 vulnerability is classified as critical with a severity value of 9.8.
What software is affected by CVE-2023-38035?
The Ivanti MobileIron Sentry versions 9.18.0 and below are affected by CVE-2023-38035.
How can an attacker exploit CVE-2023-38035?
An attacker can exploit CVE-2023-38035 by exploiting an insufficiently restrictive Apache HTTPD configuration to bypass authentication controls on the administrative interface.
Is there a fix available for CVE-2023-38035?
To fix CVE-2023-38035, it is recommended to upgrade to a version of Ivanti MobileIron Sentry that is not vulnerable.