LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-38035: Ivanti Sentry Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 22, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Sep 12, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-38035 to its Known Exploited Vulnerabilities catalog on Aug 22, 2023, with a federal patch deadline of Sep 12, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to…

CVE-2023-38035 is an authentication bypass vulnerability in Ivanti Sentry (formerly MobileIron Sentry). It can allow an unauthenticated attacker to bypass authentication controls on the administrative interface because of an insufficiently restrictive Apache HTTPD configuration. This matters because Sentry often sits at the edge of mobile device management and enterprise access environments; successful abuse of the admin interface can give an attacker a foothold for further compromise. CISA notes known ransomware use associated with this vulnerability, so organizations running the product should treat exposure as high priority and confirm all details against the vendor advisory.

How it works

The underlying weakness is CWE-863 (Incorrect Authorization). In this case, the product’s Apache HTTPD configuration does not sufficiently restrict access to administrative functionality. An attacker who can reach the administrative interface may be able to bypass normal authentication controls and interact with management features without valid credentials. Exact request paths, parameters, or exploitation mechanics are not detailed here; defenders should treat any unauthenticated access to the admin surface as the core risk and validate behavior only against the official vendor advisory and their own testing in a controlled environment. Because the flaw affects authorization on a privileged interface, successful exploitation can lead to configuration changes, credential access, or lateral movement depending on how the appliance is deployed and what it manages.

Am I affected? How to find it in your systems

Ivanti Sentry is typically deployed as a network appliance or virtual appliance supporting mobile and endpoint management, often exposed to internal management networks or, in some designs, to broader enterprise or partner networks. Inventory efforts should focus on:

Look for systems where the administrative interface is reachable from untrusted or semi-trusted segments. Telemetry that may indicate probing or exploitation includes unusual unauthenticated requests to admin paths, unexpected configuration changes, new administrative sessions or accounts, and anomalous outbound connections from the Sentry host. Correlate web and system logs with identity and network logs; absence of clear indicators does not prove non-exploitation if logging was incomplete.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation instructions for CVE-2023-38035 as published in the official Ivanti advisory. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. After patching:

Hardening for this class of issue also includes ensuring reverse-proxy or web-server rules do not expose privileged paths, keeping the appliance fully updated, and removing unused management features.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited authentication-bypass vulnerabilities, especially those with known ransomware use, frequently lead to broader compromise and data exposure. If Sentry was reachable and unpatched during the relevant window, assume the administrative interface may have been abused and investigate connected identity, device, and network systems. As a quick personal check, individuals can run a free exposure scan of their work email address against known breach datasets to see whether their credentials already appear in public dumps; organizational response should still center on full incident investigation, credential rotation, and containment rather than solely on public breach lists.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Sentry
WeaknessCWE-863
Added to CISA KEVAug 22, 2023
Federal patch deadlineSep 12, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities