CRITICAL

CVE-2023-38035

Ivanti Mobileiron Sentry 2023-08-21 CVSS v3.1
CVSS
9.8
KEV

Description

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

Summary dbcve.org

Authentication bypass vulnerability in MICS Admin Portal of Ivanti MobileIron Sentry versions 9.18.0 and below. The Apache HTTPD server configuration is insufficiently restrictive, allowing unauthenticated attackers to access the administrative interface by circumventing authentication controls.

Mitigation

Upgrade Ivanti MobileIron Sentry to a version above 9.18.0. Additionally, restrict network access to the administrative interface using firewall rules or network segmentation as a defense-in-depth measure until the upgrade can be applied.

Proof of Concept

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

99.95%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE