peter bassill · operator
$ cve CVE-2023-38035 JSON

CVE-2023-38035 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-09-12.

Description

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.95% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-863
On CISA KEVyes — remediate by 2023-09-12
Public exploitnone known
Published2023-08-21
Last modified2026-06-17

CISA KEV

NameIvanti Sentry Authentication Bypass Vulnerability
Added2023-08-22
Due2023-09-12
Vendor / productIvanti / Sentry
Ransomware useknown

Affected (1)

VendorProduct
ivantimobileiron sentry

References

→ the Explorer  ·  watch your stack  ·  NVD