Skip to content
COOEY

EXPOSURES › CVE-2023-38035

CVE-2023-38035

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-08-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-38035 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 ransomwareexploited-in-wildunpatchedauth-bypass

Ivanti Sentry's insufficiently restrictive Apache HTTPD configuration allowed attackers to bypass authentication controls on its administrative interface.

An authentication bypass vulnerability in Ivanti Sentry, formerly MobileIron Sentry, stemmed from an insufficiently restrictive Apache HTTPD configuration, enabling attackers to bypass authentication on the administrative interface. This failure is critical for DIB organizations because it directly compromises administrative access, allowing unauthorized control over device management and data, and violates CMMC/NIST 800-171 requirements for access control and system integrity. Organizations must ensure their endpoint management solutions are patched and that their Apache configurations are hardened to prevent similar bypasses.

Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating a negligent, avoidable failure where a known configuration flaw was left unpatched and unhardened.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized