Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-38035


A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.


Published

2023-08-21T17:15:47.457

Last Modified

2024-12-20T17:50:25.653

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-863
  • Type: Secondary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ivanti mobileiron_sentry ≤ 9.18.0 Yes

References