HTTP: Ivanti Sentry Authentication Bypass

This signature detects attempts to exploit a known vulnerability against Ivanti Sentry. A successful attack can lead to arbitrary code execution.

Extended Description

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

Affected Products

Ivanti mobileiron_sentry

References

CVE: CVE-2023-38035

Short Name
HTTP:CTS:IVANTI-SENTRY-BYPA
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Authentication Bypass CVE-2023-38035 Ivanti Sentry
Release Date
10/10/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3640
False Positive
Unknown
Vendors

Ivanti

Found a potential security threat?