CVE-2023-38035
Description
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
Summary dbcve.org
Authentication bypass vulnerability in MICS Admin Portal of Ivanti MobileIron Sentry versions 9.18.0 and below. The Apache HTTPD server configuration is insufficiently restrictive, allowing unauthenticated attackers to access the administrative interface by circumventing authentication controls.
Mitigation
Upgrade Ivanti MobileIron Sentry to a version above 9.18.0. Additionally, restrict network access to the administrative interface using firewall rules or network segmentation as a defense-in-depth measure until the upgrade can be applied.