CVE-2023-38035
Ivanti Sentry: Authentication Bypass
As of , CVE-2023-38035 in Ivanti Sentry is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 22 August 2023
- US federal deadline
- 12 September 202321 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Known
- EPSS score
- 0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.00 on 22 August 2023EPSS on the day CISA listed it.
- Public exploit
- 1 Metasploit module
- Fix
- Vendor advice: forums.ivanti.comLinks below, from CISA's entry.
What CISA says to do
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA's required action
What the flaw is
Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
CISA's description
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
The CVE record's description, from hackerone
- CVE published
- 21 August 2023
- Assigned by
- hackerone
- CVSS
- 9.8 Critical (CVSS 3.1, from CISA-ADP)
- CWE-863
- Incorrect Authorization
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: Ivanti Sentry MICSLogService Auth Bypass resulting in RCE (CVE-2023-38035)exploit module, rank excellent
Sentry: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-10520OS Command Injection | Ivanti Sentry | Patch this weekEPSS 0.99 | 0.99 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org