Aug. 22, 2023, 6:32 p.m. | Satnam Narang

Cyber Exposure Alerts www.tenable.com

CVE-2023-38035: Ivanti Sentry API Authentication Bypass Zero-Day Exploited in the Wild

For the third time in a month, Ivanti discloses a zero-day vulnerability in one of its products that has been exploited in the wild


Background


On August 21, Ivanti published an advisory for a critical vulnerability in Ivanti Sentry, formerly known as MobileIron Sentry, a secure mobile gateway that is part of Ivanti’s unified endpoint management (UEM) platform.







CVEDescriptionCVSSv3Severity
CVE-2023-38035Ivanti Sentry API Authentication Bypass …

advisory api api authentication august authentication authentication bypass bypass critical critical vulnerability cve exploited ivanti products sentry third vulnerability zero-day zero-day vulnerability

Azure DevSecOps Cloud Engineer II

@ Prudent Technology | McLean, VA, USA

Security Engineer III - Python, AWS

@ JPMorgan Chase & Co. | Bengaluru, Karnataka, India

SOC Analyst (Threat Hunter)

@ NCS | Singapore, Singapore

Managed Services Information Security Manager

@ NTT DATA | Sydney, Australia

Senior Security Engineer (Remote)

@ Mattermost | United Kingdom

Penetration Tester (Part Time & Remote)

@ TestPros | United States - Remote