Vulnerability record · CVE-2023-38035 · published 21 August 2023
CVE-2023-38035: Ivanti MobileIron Sentry admin portal authentication bypass
Ivanti · Mobileiron Sentry
Ivanti MobileIron Sentry versions 9.18.0 and below contain an authentication bypass in the MICS Admin Portal caused by an insufficiently restrictive Apache HTTPD configuration. An attacker can reach the administrative interface without valid credentials, which matters because that interface controls a mobile device management gateway.
Description
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable authentication bypass with CVSS 9.8, KEV listing with known ransomware use, and near-certain EPSS probability.
What it is
Ivanti MobileIron Sentry versions 9.18.0 and below contain an authentication bypass in the MICS Admin Portal caused by an insufficiently restrictive Apache HTTPD configuration. An attacker can reach the administrative interface without valid credentials, which matters because that interface controls a mobile device management gateway.
Impact
An attacker gains unauthenticated access to the Sentry administrative interface, with high confidentiality, integrity and availability impact per the CVSS vector, and public reporting describes remote code execution following the bypass.
Attack surface
Reachable over the network via the administrative interface's API, with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). The flaw is in the Apache HTTPD configuration fronting the MICS Admin Portal.
Exploitation
Listed in CISA KEV since 2023-08-22 with known ransomware campaign use, and EPSS 30-day probability is 0.9995 (99.97th percentile). Public exploit code is referenced by Packet Storm, so exploitation is both observed and widely available.
What to do
- Upgrade MobileIron Sentry to a version above 9.18.0 per the Ivanti advisory; patch first.
- If patching is not immediately possible, restrict network access to the MICS Admin Portal and its API to trusted management networks only.
- Apply the vendor's configuration mitigations for the Apache HTTPD front end as described in the Ivanti advisory.
- Discontinue use of the product if no mitigation is available, as directed by CISA KEV required action.
- Audit admin accounts and credentials on Sentry for signs of unauthorized changes after exposure.
Detection
- Review Sentry and Apache HTTPD logs for unauthenticated or anomalous requests to MICS Admin Portal API endpoints.
- Hunt for unexpected administrative logins, configuration changes, or new accounts on Sentry appliances.
- Monitor for outbound connections or process execution on Sentry hosts consistent with post-exploitation remote code execution.
- Check network telemetry for external hosts reaching the Sentry admin interface from outside trusted management ranges.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-38035 to the Known Exploited Vulnerabilities catalog on 22 August 2023 as "Ivanti Sentry Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 12 September 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/174643/Ivanti-Sentry-Authentication-Bypass-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface | Vendor Advisory |
| http://packetstormsecurity.com/files/174643/Ivanti-Sentry-Authentication-Bypass-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38035 | US Government Resource |
Track CVE-2023-38035 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-38035), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.