🛡 CVE-2023-38035
Ivanti Sentry Authentication Bypass Vulnerability
Ivanti Sentry CWE-863
Ransomware use
KNOWN
CISA KEV
EPSS
99.9%
Likely exploited · 100th pct
Added to KEV
2023-08-22
CISA
Remediate by
2023-09-12
⚠ OVERDUE
CWE
CWE-863
weakness
📈 EPSS exploit probability
99.9%
FIRST EPSS — 30-day probability of exploitation in the wild · band Likely exploited · higher than 100% of all scored CVEs
⚠ KEV remediation overdue
CISA required federal remediation by 2023-09-12. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.
📄 Description
Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTT
🏹 Attributed exploitation
Malware / ransomware (KEV): ransomware (KEV-flagged)
🔗 External references & OSINT
🔄 Internal pivots & actions
🛡 Add to case
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron