EXPOSURES › CVE-2023-38035
CVE-2023-38035
CRITICAL ⌖ ON CISA KEV · EXPLOITEDIvanti Sentry's insufficiently restrictive Apache HTTPD configuration allowed attackers to bypass authentication controls on its administrative interface.
An authentication bypass vulnerability in Ivanti Sentry, formerly MobileIron Sentry, stemmed from an insufficiently restrictive Apache HTTPD configuration, enabling attackers to bypass authentication on the administrative interface. This failure is critical for DIB organizations because it directly compromises administrative access, allowing unauthorized control over device management and data, and violates CMMC/NIST 800-171 requirements for access control and system integrity. Organizations must ensure their endpoint management solutions are patched and that their Apache configurations are hardened to prevent similar bypasses.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating a negligent, avoidable failure where a known configuration flaw was left unpatched and unhardened.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |