S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-38035 Scanner

Detects 'Authentication Bypass' vulnerability in Ivanti MobileIron Sentry affects v. 9.18.0 and below.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
6.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-38035
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
MobileIron Sentryby Ivanti
AFFECTED< 9.18.0 and belowSAFE ✓≥ 9.18.0 and below
mobileiron_sentryby ivanti
0
Updated Sep 10, 2026View on NVD →
Detail

Ivanti MobileIron Sentry is a mobile device management solution used by organizations to secure and manage their mobile devices. It ensures that devices accessing company data and networks are compliant and secure. Ivanti MobileIron Sentry is popular with many large enterprises because it can be managed from a single console, regardless of the number of devices being managed. This makes device management much easier and more efficient.

The CVE-2023-38035 vulnerability, detected in Ivanti MobileIron Sentry versions 9.18.0 and below, is an issue that can allow attackers to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration. The vulnerability could be exploited by hackers to gain unauthorized access to sensitive data such as usernames, passwords, and other confidential information. The severity level of this vulnerability is high because it can compromise the entire system.

When this vulnerability is exploited, it can lead to severe consequences for organizations. Hackers can easily manipulate sensitive data stored on the device and steal sensitive business information. This not only puts the organization at risk, but it also puts the personal information of employees and customers in danger. If sensitive data of critical systems is compromised, it can cause a severe impact on the organization's overall operations, resulting in data loss, financial losses, and reputation damage.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The platform offers comprehensive security scans and regular vulnerability assessments, which can help businesses stay one step ahead of potential threats. With s4e.io, organizations can ensure that their devices are secure and compliant at all times.

 

REFERENCES

Solution Advice

Precautions can prevent this vulnerability from being exploited. Here are some measures that IT departments can take to protect their Ivanti MobileIron Sentry devices from this vulnerability:

  • Ensure regular software updates, which should include the latest security patches.
  • Use remote monitoring and management tools to detect potential security threats.
  • Deploy strong authentication and encryption protocols to protect sensitive data.
  • Implement a firewall or intrusion detection system to monitor all incoming and outgoing traffic.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.