CVE-2023-38035
Last modified
CVE-2023-38035 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.95% chance of exploitation in the next 30 days.
Description
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Mobileiron Sentry | <= 9.18.0 |
References
- http://packetstormsecurity.com/files/174643/Ivanti-Sentry-Authentication-Bypass-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/174643/Ivanti-Sentry-Authentication-Bypass-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38035US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-38035?
How severe is CVE-2023-38035?
How do I fix CVE-2023-38035?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-3803A vulnerability classified as problematic has been found in …3.7
- CVE-2023-38030 Saho’s attendance devices ADM100 and ADM-100FP have a vulne…7.5
- CVE-2023-38031 ASUS RT-AC86U Adaptive QoS - Web History function has insuf…8.8
- CVE-2023-38032 ASUS RT-AC86U AiProtection security- related function has i…8.8
- CVE-2023-38033 ASUS RT-AC86U unused Traffic Analyzer legacy Statistic func…8.8
- CVE-2023-38034A command injection vulnerability in the DHCP Client functio…9.8
- CVE-2023-38036A security vulnerability within Ivanti Avalanche Manager bef…9.8
- CVE-2023-38037ActiveSupport::EncryptedFile writes contents that will be en…5.5
- CVE-2023-38039When curl retrieves an HTTP response, it stores the incoming…7.5
- CVE-2023-3804A vulnerability classified as problematic was found in Cheng…9.8
- CVE-2023-38040A reflected XSS vulnerability exists in Revive Adserver 5.4.…6.1
- CVE-2023-38041A logged in user may elevate its permissions by abusing a Ti…7
Are you affected by CVE-2023-38035?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
