CVE-2023-38035
Critical CVSS 9.8 Known exploitedPublished 2023-08-21 · last changed 2026-06-17 · added to CISA KEV 2023-08-22
The fix
We hold no Microsoft remediation data for CVE-2023-38035, which normally means it is not a Windows CVE. For non-Microsoft software the fix is the vendor's own updated release, and the affected versions are listed below.
What it is
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
Sources
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H