CVE-2023-38035
Act now ● On CISA KEV — actively exploited used in ransomware
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
100.0%
100.0th percentile
CISA KEV
Listed
Added 2023-08-22 · patch by 2023-09-12
Weakness / dates
—
Published — · modified —
Timeline
- 2023-08-22 — Added to CISA KEV (actively exploited)
- 2023-09-12 — CISA patch-by deadline
Description
Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.